VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,399)

page 131 of 170
  • CVE-2021-26346MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

  • CVE-2022-44432MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

  • CVE-2022-44426MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

  • CVE-2022-44425MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

  • CVE-2022-42765MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42764MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-42763MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-39343MedNov 8, 2022
    risk 0.36cvss 5.6epss 0.01

    Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2.0, the Fault Tolerant feature of Azure RTOS FileX includes integer under and overflows which may be exploited to achieve buffer overflow and modify memory…

  • CVE-2022-39105MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

  • CVE-2021-33439MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is Integer overflow in gc_compact_strings() in mjs.c.

  • CVE-2022-29358MedMay 25, 2022
    risk 0.36cvss 5.5epss 0.01

    epub2txt2 v2.04 was discovered to contain an integer overflow via the function bug in _parse_special_tag at sxmlc.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted XML file.

  • CVE-2022-29030MedMay 20, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The Mono_Loader.dll library is vulnerable to integer overflow condition while parsing…

  • CVE-2022-1475MedMay 2, 2022
    risk 0.36cvss 5.5epss 0.01

    An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavcodec/g729_parser.c when processing a specially crafted file.

  • CVE-2022-27148MedApr 8, 2022
    risk 0.36cvss 5.5epss 0.01

    GPAC mp4box 1.1.0-DEV-rev1663-g881c6a94a-master is vulnerable to Integer Overflow.

  • CVE-2021-3933MedMar 25, 2022
    risk 0.36cvss 5.5epss 0.01

    An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.

  • CVE-2021-3428MedMar 4, 2022
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the Linux kernel. A denial of service problem is identified if an extent tree is corrupted in a crafted ext4 filesystem in fs/ext4/extents.c in ext4_es_cache_extent. Fabricating an integer overflow, A local attacker with a special user privilege may cause a…

  • CVE-2021-22441MedFeb 25, 2022
    risk 0.36cvss 5.5epss 0.00

    Some Huawei products have an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to kernel crash.

  • CVE-2021-46667MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.

  • CVE-2021-0623MedNov 18, 2021
    risk 0.36cvss 5.5epss 0.00

    In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05585817.

  • CVE-2021-0621MedNov 18, 2021
    risk 0.36cvss 5.5epss 0.00

    In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05561383.