VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,583)

page 17 of 180
  • CVE-2026-21385HigKEVMar 2, 2026
    risk 0.63cvss 7.8epss 0.01

    Memory corruption while using alignments for memory allocation.

  • CVE-2025-24985HigKEVMar 11, 2025
    risk 0.63cvss 7.8epss 0.04

    Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

  • CVE-2024-38080HigKEVJul 9, 2024
    risk 0.63cvss 7.8epss 0.07

    Windows Hyper-V Elevation of Privilege Vulnerability

  • CVE-2023-21823HigKEVFeb 14, 2023
    risk 0.63cvss 7.8epss 0.06

    Windows Graphics Component Remote Code Execution Vulnerability

  • CVE-2021-30952HigKEVAug 24, 2021
    risk 0.63cvss 7.8epss 0.07

    An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-21223CriApr 26, 2021
    risk 0.63cvss 9.6epss 0.01

    Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2013-3486CriJan 27, 2020
    risk 0.63cvss 9.6epss 0.02

    IrfanView FlashPix Plugin 4.3.4 0 has an Integer Overflow Vulnerability

  • CVE-2026-91728CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-87643CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17726CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17717CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17682CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17673CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-11088CriJun 4, 2026
    risk 0.62cvss 9.6epss 0.00

    Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-22721CriMar 14, 2022
    risk 0.62cvss 9.1epss 0.42

    If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

  • CVE-2021-30860HigKEVAug 24, 2021
    risk 0.62cvss 7.8epss 0.76

    An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a…

  • CVE-2022-22105CriSep 16, 2022
    risk 0.61cvss 9.4epss 0.01

    Memory corruption in bluetooth due to integer overflow while processing HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2019-5789HigMay 23, 2019
    risk 0.61cvss 8.8epss 0.09

    An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

  • CVE-2019-5788HigMay 23, 2019
    risk 0.61cvss 8.8epss 0.09

    An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

  • CVE-2018-6092HigDec 4, 2018
    risk 0.61cvss 8.8epss 0.09

    An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.