VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,593)

page 170 of 180
  • CVE-2007-2949Jul 4, 2007
    risk 0.01cvss —epss 0.07

    Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value.

  • CVE-2026-54920NonAug 25, 2026
    risk 0.00cvss 0.0epss 0.00

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a crafted HTJ2K-compressed EXR file to cause an…

  • CVE-2026-61799Aug 20, 2026
    risk 0.00cvss —epss —

    ## Summary `io.netty.incubator:netty-incubator-codec-bhttp` uses attacker-controlled Binary HTTP variable-length integers as `long` values but accumulates them into `int` offsets. Large valid varint lengths wrap the internal offset negative, leading to unchecked…

  • CVE-2026-64694CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.01

    An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-43780HigJul 27, 2026
    risk 0.00cvss 7.8epss 0.00

    An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted texture may lead to unexpected…

  • CVE-2026-43764CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.01

    An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-59117HigJul 16, 2026
    risk 0.00cvss 7.5epss 0.01

    Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58594HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58532HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-56647HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-56194HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-56182HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55057MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.01

    Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

  • CVE-2026-55048HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-55043HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

  • CVE-2026-55033HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.01

    Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-55026MedJul 14, 2026
    risk 0.00cvss 6.2epss 0.00

    Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

  • CVE-2026-54124HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

  • CVE-2026-54115HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50435HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.