CWE-190
Integer Overflow or Wraparound
Description
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,593)
page 171 of 180| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-50347 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-50310 | Med | 0.00 | 4.7 | 0.00 | Jul 14, 2026 | Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally. | ||
| CVE-2026-50306 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-55012 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-54109 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | ||
| CVE-2026-50299 | Med | 0.00 | 6.8 | 0.00 | Jul 14, 2026 | Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. | ||
| CVE-2026-50298 | Med | 0.00 | 6.8 | 0.00 | Jul 14, 2026 | Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. | ||
| CVE-2026-49800 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49168 | Med | 0.00 | 6.8 | 0.00 | Jul 14, 2026 | Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. | ||
| CVE-2026-39042 | Hig | 0.00 | 7.5 | 0.01 | Jul 13, 2026 | An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so. | ||
| CVE-2026-40469 | Cri | 0.00 | 9.1 | 0.00 | Jul 13, 2026 | Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below. | ||
| CVE-2026-40468 | Cri | 0.00 | 9.1 | 0.00 | Jul 13, 2026 | Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions… | ||
| CVE-2026-7162 | Hig | 0.00 | 7.8 | 0.00 | Jul 13, 2026 | Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software. | ||
| CVE-2026-53482 | Hig | 0.00 | 7.5 | 0.00 | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Integer overflow or wraparound vulnerability. An… | ||
| CVE-2026-53763 | Low | 0.00 | 3.8 | 0.00 | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.0.0 and prior to version 4.11.0, 32-bit integer overflows in OP-TEE core's AES-GCM… | ||
| CVE-2026-57974 | Hig | 0.00 | 8.8 | 0.01 | Jul 3, 2026 | Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-46463 | Med | 0.00 | 6.5 | 0.00 | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an integer overflow or wraparound vulnerability. An… | ||
| CVE-2026-14430 | Hig | 0.00 | 8.8 | 0.00 | Jul 1, 2026 | Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-14391 | Med | 0.00 | 5.3 | 0.00 | Jul 1, 2026 | Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-6682 | Hig | 0.00 | 7.6 | 0.00 | Jul 1, 2026 | In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlled file-size metadata and unsafe read lengths in downstream callers. This maps to CWE-190 (Integer Overflow or Wraparound).… |
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 4.7epss 0.00
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
- risk 0.00cvss 6.8epss 0.00
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.
- risk 0.00cvss 6.8epss 0.00
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
- risk 0.00cvss 7.8epss 0.00
Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.8epss 0.00
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.
- risk 0.00cvss 7.5epss 0.01
An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.
- risk 0.00cvss 9.1epss 0.00
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
- risk 0.00cvss 9.1epss 0.00
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions…
- risk 0.00cvss 7.8epss 0.00
Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software.
- risk 0.00cvss 7.5epss 0.00
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Integer overflow or wraparound vulnerability. An…
- risk 0.00cvss 3.8epss 0.00
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.0.0 and prior to version 4.11.0, 32-bit integer overflows in OP-TEE core's AES-GCM…
- risk 0.00cvss 8.8epss 0.01
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 6.5epss 0.00
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an integer overflow or wraparound vulnerability. An…
- risk 0.00cvss 8.8epss 0.00
Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- risk 0.00cvss 5.3epss 0.00
Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.00cvss 7.6epss 0.00
In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlled file-size metadata and unsafe read lengths in downstream callers. This maps to CWE-190 (Integer Overflow or Wraparound).…