VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,387)

page 155 of 170
  • CVE-2026-55048HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-55043HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

  • CVE-2026-55033HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.01

    Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-55026MedJul 14, 2026
    risk 0.00cvss 6.2epss 0.00

    Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

  • CVE-2026-54124HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

  • CVE-2026-54115HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50435HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50347HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.

  • CVE-2026-50310MedJul 14, 2026
    risk 0.00cvss 4.7epss 0.00

    Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.

  • CVE-2026-50306HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55012HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.

  • CVE-2026-54109HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

  • CVE-2026-50299MedJul 14, 2026
    risk 0.00cvss 6.8epss 0.00

    Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.

  • CVE-2026-50298MedJul 14, 2026
    risk 0.00cvss 6.8epss 0.00

    Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.

  • CVE-2026-49800HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.02

    Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-49168MedJul 14, 2026
    risk 0.00cvss 6.8epss 0.00

    Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

  • CVE-2026-39042HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.

  • CVE-2026-40469CriJul 13, 2026
    risk 0.00cvss 9.1epss 0.00

    Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.

  • CVE-2026-40468CriJul 13, 2026
    risk 0.00cvss 9.1epss 0.00

    Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions…

  • CVE-2026-7162HigJul 13, 2026
    risk 0.00cvss 7.8epss 0.00

    Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software.