VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,387)

page 154 of 170
  • CVE-2012-5835Nov 21, 2012
    risk 0.01cvss epss 0.09

    Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service…

  • CVE-2009-2949Feb 16, 2010
    risk 0.01cvss epss 0.14

    Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.

  • CVE-2009-3909Nov 19, 2009
    risk 0.01cvss epss 0.09

    Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow.

  • CVE-2009-1570Nov 13, 2009
    risk 0.01cvss epss 0.08

    Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a BMP file with crafted width and height values that trigger a heap-based buffer overflow.

  • CVE-2009-0946Apr 17, 2009
    risk 0.01cvss epss 0.09

    Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.

  • CVE-2007-2834Sep 18, 2007
    risk 0.01cvss epss 0.11

    Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an…

  • CVE-2007-3387Jul 30, 2007
    risk 0.01cvss epss 0.09

    Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted…

  • CVE-2007-2949Jul 4, 2007
    risk 0.01cvss epss 0.07

    Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value.

  • CVE-2026-64694CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-43780HigJul 27, 2026
    risk 0.00cvss 7.8epss 0.00

    An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted texture may lead to unexpected…

  • CVE-2026-43764CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-59117HigJul 16, 2026
    risk 0.00cvss 7.5epss 0.00

    Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.

  • CVE-2026-48354MedJul 14, 2026
    risk 0.00cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this…

  • CVE-2026-48342HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-58594HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58532HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-56647HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-56194HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-56182HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55057MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.