VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,387)

page 149 of 170
  • CVE-2026-27781LowMay 19, 2026
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

  • CVE-2026-4985MedMar 27, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the file src/cgif.c of the component GIF Image Handler. The manipulation of the argument width/height leads to integer overflow. The attack may be initiated…

  • CVE-2026-2271LowMar 26, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file…

  • CVE-2023-29144LowDec 12, 2025
    risk 0.21cvss 3.3epss 0.00

    Malwarebytes 1.0.14 for Linux doesn't properly compute signatures in some scenarios. This allows a bypass of detection.

  • CVE-2023-28903LowJun 28, 2025
    risk 0.21cvss 3.3epss 0.00

    An integer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause a denial-of-service of the infotainment system.

  • CVE-2025-5001LowMay 20, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The manipulation of the argument -l leads to integer overflow. Local access is required…

  • CVE-2025-29087LowApr 7, 2025
    risk 0.21cvss 3.2epss 0.00

    In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in…

  • CVE-2023-34406LowFeb 13, 2025
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered on Mercedes Benz NTG 6. A possible integer overflow exists in the user data import/export function of NTG (New Telematics Generation) 6 head units. To perform this attack, local access to USB interface of the car is needed. With prepared data, an attacker…

  • CVE-2024-28044LowSep 2, 2024
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow.

  • CVE-2024-3757LowMay 7, 2024
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through integer overflow.

  • CVE-2024-31047LowApr 8, 2024
    risk 0.21cvss 3.3epss 0.00

    An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the convert function of exrmultipart.cpp.

  • CVE-2020-19909LowAug 22, 2023
    risk 0.21cvss 3.3epss 0.00

    Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties report that this has no direct security impact on the curl user; however, it may (in theory) cause a denial of service to associated systems or networks if,…

  • CVE-2022-42767LowDec 6, 2022
    risk 0.21cvss 3.3epss 0.00

    In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

  • CVE-2022-21733MedFeb 3, 2022
    risk 0.21cvss 4.3epss 0.01

    Tensorflow is an Open Source Machine Learning Framework. The implementation of `StringNGrams` can be used to trigger a denial of service attack by causing an out of memory condition after an integer overflow. We are missing a validation on `pad_witdh` and that result in…

  • CVE-2020-11869LowApr 27, 2020
    risk 0.21cvss 3.3epss 0.00

    An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati-2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could abuse this…

  • CVE-2016-9085LowFeb 3, 2017
    risk 0.21cvss 3.3epss 0.00

    Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.

  • CVE-2026-19167LowAug 6, 2026
    risk 0.20cvss 3.1epss 0.00

    Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-33596LowApr 22, 2026
    risk 0.20cvss 3.1epss 0.00

    A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend.

  • CVE-2021-46750LowSep 6, 2025
    risk 0.20cvss 3.0epss 0.00

    Failure to validate the address and size in TEE (Trusted Execution Environment) may allow a malicious x86 attacker to send malformed messages to the graphics mailbox resulting in an overlap of a TMR (Trusted Memory Region) that was previously allocated by the ASP bootloader…

  • CVE-2026-16517LowJul 21, 2026
    risk 0.19cvss 2.9epss 0.00

    A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the…