CWE-190
Integer Overflow or Wraparound
Description
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,596)
page 124 of 180| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-5000 | Med | 0.43 | 6.5 | 0.14 | Jul 9, 2018 | Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure. | ||
| CVE-2018-13785 | Med | 0.43 | 6.5 | 0.04 | Jul 9, 2018 | In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service. | ||
| CVE-2016-5844 | Med | 0.43 | 6.5 | 0.04 | Sep 21, 2016 | Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file. | ||
| CVE-2026-107217 | Hig | 0.42 | 7.5 | — | Oct 7, 2026 | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting… | ||
| CVE-2026-102805 | Med | 0.42 | 6.5 | 0.00 | Sep 30, 2026 | A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be… | ||
| CVE-2026-102804 | Med | 0.42 | 6.5 | 0.00 | Sep 30, 2026 | A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote… | ||
| CVE-2026-101279 | Med | 0.42 | 6.5 | 0.00 | Sep 29, 2026 | A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the argument pct leads to integer overflow. Remote… | ||
| CVE-2025-14181 | Med | 0.42 | 6.5 | 0.00 | Sep 25, 2026 | The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make the client allocate a buffer far smaller… | ||
| CVE-2026-63126 | Hig | 0.42 | 7.5 | 0.01 | Sep 16, 2026 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary before advancing cursors, pointers, limits,… | ||
| CVE-2026-84536 | Med | 0.42 | 6.5 | 0.00 | Sep 14, 2026 | An integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to unexpected system termination. | ||
| CVE-2026-84487 | Med | 0.42 | 6.5 | 0.00 | Sep 14, 2026 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may result… | ||
| CVE-2026-90596 | Med | 0.42 | 6.5 | 0.01 | Sep 13, 2026 | A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the… | ||
| CVE-2026-77896 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-69734 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-67641 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network. | ||
| CVE-2026-82076 | Med | 0.42 | 6.5 | 0.00 | Sep 8, 2026 | An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal resource limit. Submitting a specially crafted query causes the server to consume memory without bound… | ||
| CVE-2026-48486 | Hig | 0.42 | 7.5 | 0.00 | Sep 3, 2026 | Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in BlockServiceImpl.applyBlock() allowed a miner to receive an arbitrarily inflated block reward by crafting a… | ||
| CVE-2026-38343 | Med | 0.42 | 6.5 | 0.00 | Aug 28, 2026 | An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file. | ||
| CVE-2026-30045 | Hig | 0.42 | 7.5 | 0.01 | Aug 27, 2026 | An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET request. | ||
| CVE-2026-55648 | Hig | 0.42 | 7.5 | 0.00 | Aug 19, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-bit arithmetic. A malicious RDP server can… |
- risk 0.43cvss 6.5epss 0.14
Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure.
- risk 0.43cvss 6.5epss 0.04
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
- risk 0.43cvss 6.5epss 0.04
Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.
- risk 0.42cvss 7.5epss —
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting…
- risk 0.42cvss 6.5epss 0.00
A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be…
- risk 0.42cvss 6.5epss 0.00
A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote…
- risk 0.42cvss 6.5epss 0.00
A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the argument pct leads to integer overflow. Remote…
- risk 0.42cvss 6.5epss 0.00
The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make the client allocate a buffer far smaller…
- risk 0.42cvss 7.5epss 0.01
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary before advancing cursors, pointers, limits,…
- risk 0.42cvss 6.5epss 0.00
An integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to unexpected system termination.
- risk 0.42cvss 6.5epss 0.00
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may result…
- risk 0.42cvss 6.5epss 0.01
A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the…
- risk 0.42cvss 6.5epss 0.01
Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.00
An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal resource limit. Submitting a specially crafted query causes the server to consume memory without bound…
- risk 0.42cvss 7.5epss 0.00
Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in BlockServiceImpl.applyBlock() allowed a miner to receive an arbitrarily inflated block reward by crafting a…
- risk 0.42cvss 6.5epss 0.00
An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.
- risk 0.42cvss 7.5epss 0.01
An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET request.
- risk 0.42cvss 7.5epss 0.00
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-bit arithmetic. A malicious RDP server can…