VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,387)

page 151 of 170
  • CVE-2026-14786LowJul 6, 2026
    risk 0.14cvss 3.3epss 0.00

    A security flaw has been discovered in radareorg radare2 up to 6.1.6. This impacts the function r_str_word_get0set of the file libr/util/str.c. The manipulation results in integer overflow. The attack must be initiated from a local position. The exploit has been released to the…

  • CVE-2026-14761LowJul 5, 2026
    risk 0.14cvss 3.3epss 0.00

    A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/r_str_append of the file libr/util/str.c. The manipulation leads to integer overflow. An attack has to be approached locally. The exploit has been…

  • CVE-2026-14758LowJul 5, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of the file libr/core/cmd_anal.inc.c of the component hexpairs Parser. Such manipulation leads to integer overflow. The attack needs to be performed locally.…

  • CVE-2026-56363LowJun 30, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. An attacker can supply a large binomial kernel value causing integer overflow, resulting in division by zero and application…

  • CVE-2026-10722LowJun 3, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be…

  • CVE-2026-10268LowJun 1, 2026
    risk 0.14cvss 3.3epss 0.00

    A weakness has been identified in janet-lang janet up to 1.41.0. This vulnerability affects the function unmarshal_one_fiber of the file src/core/marsh.c. Executing a manipulation can lead to integer overflow. It is possible to launch the attack on the local host. The exploit…

  • CVE-2026-39824LowMay 22, 2026
    risk 0.14cvss 3.3epss 0.00

    NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.

  • CVE-2026-6192LowApr 13, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and…

  • CVE-2026-3284LowFeb 27, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires a local approach. The exploit has been made…

  • CVE-2025-2574LowMar 20, 2025
    risk 0.14cvss epss 0.00

    Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.

  • CVE-2022-0185HigKEVFeb 11, 2022
    risk 0.14cvss 8.4epss 0.25

    A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs…

  • CVE-2021-20203LowFeb 25, 2021
    risk 0.14cvss 3.2epss 0.01

    An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the…

  • CVE-2020-11526LowMay 15, 2020
    risk 0.14cvss 2.2epss 0.02

    libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.

  • CVE-2026-29776LowMar 13, 2026
    risk 0.13cvss 3.1epss 0.00

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library This vulnerability is fixed in 3.24.0.

  • CVE-2024-21105LowApr 16, 2024
    risk 0.13cvss 2.0epss 0.00

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise…

  • CVE-2024-1633LowFeb 19, 2024
    risk 0.13cvss 2.0epss 0.00

    During the secure boot, bl2 (the second stage of the bootloader) loops over images defined in the table “bl2_mem_params_descs”. For each image, the bl2 reads the image length and destination from the image’s certificate. Because of the way of reading from the image, which…

  • CVE-2023-40218LowSep 12, 2023
    risk 0.13cvss 2.0epss 0.00

    An issue was discovered in the NPU kernel driver in Samsung Exynos Mobile Processor 9820, 980, 2100, 2200, 1280, and 1380. An integer overflow can bypass detection of error cases via a crafted application.

  • CVE-2023-40353LowSep 8, 2023
    risk 0.13cvss 2.0epss 0.00

    An issue was discovered in Exynos Mobile Processor 980 and 2100. An integer overflow at a buffer index can prevent the execution of requested services via a crafted application.

  • CVE-2021-26380LowMay 15, 2026
    risk 0.12cvss epss 0.00

    A compromised Trusted OS (TOS) driver could issue a malformed call that could potentially allow memory access outside the intended range resulting in loss of integrity.

  • CVE-2014-0569Oct 15, 2014
    risk 0.10cvss epss 0.92

    Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to…