VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,596)

page 136 of 180
  • CVE-2025-22055HigApr 16, 2025
    risk 0.39cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net: fix geneve_opt length integer overflow struct geneve_opt uses 5 bit length for each single option, which means every vary size option should be smaller than 128 bytes. However, all current related…

  • CVE-2024-45779MedMar 3, 2025
    risk 0.39cvss 6.0epss 0.00

    An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails to validate the number of extent entries to be read. A crafted or corrupted BFS filesystem may cause an integer overflow during the file…

  • CVE-2024-57262HigFeb 19, 2025
    risk 0.39cvss 7.1epss 0.00

    In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite, a related issue to CVE-2024-57256.

  • CVE-2024-57261HigFeb 19, 2025
    risk 0.39cvss 7.1epss 0.00

    In barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-57258.

  • CVE-2024-51737HigJan 8, 2025
    risk 0.39cvss 7.0epss 0.00

    RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticated redis user executing FT.SEARCH or FT.AGGREGATE with a specially crafted LIMIT command argument, or FT.SEARCH with a specially crafted KNN command argument,…

  • CVE-2024-51480HigJan 8, 2025
    risk 0.39cvss 7.0epss 0.00

    RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYINDEX, TS.MGET, TS.MRAGE, TS.MREVRANGE by an authenticated user, using specially crafted command arguments may cause an integer overflow, a subsequent heap…

  • CVE-2024-30212HigMay 28, 2024
    risk 0.39cvss —epss 0.01

    If a SCSI READ(10) command is initiated via USB using the largest LBA (0xFFFFFFFF) with it's default block size of 512 and a count of 1, the first 512 byte of the 0x80000000 memory area is returned to the user. If the block count is increased, the full RAM can be exposed. …

  • CVE-2023-22443MedMay 10, 2023
    risk 0.39cvss 6.0epss 0.00

    Integer overflow in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable denial of service via local access.

  • CVE-2022-36008HigAug 19, 2022
    risk 0.39cvss 7.1epss 0.01

    Frontier is Substrate's Ethereum compatibility layer. A security issue was discovered affecting parsing of the RPC result of the exit reason in case of EVM reversion. In release build, this would cause the exit reason being incorrectly parsed and returned by RPC. In debug build,…

  • CVE-2021-3607MedFeb 24, 2022
    risk 0.39cvss 6.0epss 0.00

    An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make…

  • CVE-2021-29605HigMay 14, 2021
    risk 0.39cvss 7.1epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. The TFLite code for allocating `TFLiteIntArray`s is vulnerable to an integer overflow issue(https://github.com/tensorflow/tensorflow/blob/4ceffae632721e52bf3501b736e4fe9d1221cdfa/tensorflow/lite/c/common.c#L24…

  • CVE-2020-10726MedMay 20, 2020
    risk 0.39cvss 6.0epss 0.00

    A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of…

  • CVE-2018-6191MedJan 24, 2018
    risk 0.39cvss 5.5epss 0.05

    The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation.

  • CVE-2026-84554MedSep 14, 2026
    risk 0.38cvss 5.9epss 0.00

    An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to cause a denial-of-service.

  • CVE-2026-86139MedSep 5, 2026
    risk 0.38cvss 6.9epss 0.00

    In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

  • CVE-2026-86138MedSep 5, 2026
    risk 0.38cvss 6.9epss 0.00

    In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

  • CVE-2026-47857MedAug 27, 2026
    risk 0.38cvss 5.9epss 0.00

    In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier

  • CVE-2026-56408MedJun 21, 2026
    risk 0.38cvss 6.9epss 0.00

    libexpat before 2.8.2 has an integer overflow in copyString.

  • CVE-2026-34219MedMar 31, 2026
    risk 0.38cvss 5.9epss 0.01

    libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an…

  • CVE-2026-25210MedJan 30, 2026
    risk 0.38cvss 6.9epss 0.00

    In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.