VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,399)

page 118 of 170
  • CVE-2023-32058HigMay 11, 2023
    risk 0.42cvss 7.5epss 0.01

    Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, due to missing overflow check for loop variables, by assigning the iterator of a loop to a variable, it is possible to overflow the type of the latter. The issue seems to happen…

  • CVE-2023-27354MedApr 20, 2023
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of the SMB directory…

  • CVE-2023-25662HigMar 25, 2023
    risk 0.42cvss 7.5epss 0.00

    TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 are vulnerable to integer overflow in EditDistance. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.

  • CVE-2023-24906MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

  • CVE-2023-24863MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

  • CVE-2023-24180MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Libelfin v0.3 was discovered to contain an integer overflow in the load function at elf/mmap_loader.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted elf file.

  • CVE-2022-25147MedJan 31, 2023
    risk 0.42cvss 6.5epss 0.01

    Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions.

  • CVE-2023-22895HigJan 10, 2023
    risk 0.42cvss 7.5epss 0.01

    The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an integer overflow in mem.rs. NOTE: this is unrelated to the https://crates.io/crates/bzip2-rs product.

  • CVE-2022-31630MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.02

    In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can…

  • CVE-2022-41550MedOct 11, 2022
    risk 0.42cvss 6.5epss 0.01

    GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header.

  • CVE-2021-20304HigAug 23, 2022
    risk 0.42cvss 7.5epss 0.02

    A flaw was found in OpenEXR's hufDecode functionality. This flaw allows an attacker who can pass a crafted file to be processed by OpenEXR, to trigger an undefined right shift error. The highest threat from this vulnerability is to system availability.

  • CVE-2022-38216HigAug 16, 2022
    risk 0.42cvss 7.5epss 0.01

    An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for…

  • CVE-2022-31005HigMay 31, 2022
    risk 0.42cvss 7.5epss 0.02

    Vapor is an HTTP web framework for Swift. Users of Vapor prior to version 4.60.3 with FileMiddleware enabled are vulnerable to an integer overflow vulnerability that can crash the application. Version 4.60.3 contains a patch for this issue. As a workaround, disable…

  • CVE-2022-29219HigMay 24, 2022
    risk 0.42cvss 7.5epss 0.01

    Lodestar is a TypeScript implementation of the Ethereum Consensus specification. Prior to version 0.36.0, there is a possible consensus split given maliciously-crafted `AttesterSlashing` or `ProposerSlashing` being included on-chain. Because the developers represent `uint64`…

  • CVE-2022-31264HigMay 21, 2022
    risk 0.42cvss 7.5epss 0.01

    Solana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF program.

  • CVE-2022-26073MedMay 5, 2022
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to a device reboot. An attacker can send packets to trigger this vulnerability.

  • CVE-2022-28471MedMay 5, 2022
    risk 0.42cvss 6.5epss 0.01

    In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfif.c. This is due to the incomplete patch for issue 38

  • CVE-2021-27411MedMay 3, 2022
    risk 0.42cvss 6.5epss 0.01

    Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as very small…

  • CVE-2022-1036HigMar 22, 2022
    risk 0.42cvss 7.5epss 0.01

    Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.

  • CVE-2022-0913HigMar 11, 2022
    risk 0.42cvss 7.5epss 0.01

    Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.