VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,583)

page 18 of 180
  • CVE-2018-12293HigJun 19, 2018
    risk 0.61cvss 8.8epss 0.10

    The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer…

  • CVE-2026-9621CriSep 1, 2026
    risk 0.60cvss —epss 0.00

    A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover

  • CVE-2026-19313CriAug 28, 2026
    risk 0.60cvss —epss 0.00

    An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

  • CVE-2026-16416CriJul 21, 2026
    risk 0.60cvss 9.3epss 0.00

    Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

  • CVE-2024-38144HigAug 13, 2024
    risk 0.60cvss 8.8epss 0.32

    Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

  • CVE-2023-33032CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.

  • CVE-2022-33269CriApr 13, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.

  • CVE-2022-33219CriJan 9, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer.

  • CVE-2022-28615CriJun 9, 2022
    risk 0.60cvss 9.1epss 0.06

    Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua…

  • CVE-2021-30275CriJan 3, 2022
    risk 0.60cvss 9.3epss 0.00

    Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired…

  • CVE-2016-2177CriJun 20, 2016
    risk 0.60cvss 9.8epss 0.45

    OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc…

  • CVE-2008-1083HigApr 8, 2008
    risk 0.60cvss 8.1epss 0.57

    Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers…

  • CVE-2026-51536CriJul 13, 2026
    risk 0.59cvss 9.1epss 0.00

    In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream length calculated as an int is passed to a downstream function that expects an…

  • CVE-2025-3500CriDec 1, 2025
    risk 0.59cvss 9.0epss 0.00

    Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

  • CVE-2025-7458CriJul 29, 2025
    risk 0.59cvss 9.1epss 0.00

    An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT…

  • CVE-2024-53146CriDec 24, 2024
    risk 0.59cvss 9.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding into several steps so…

  • CVE-2024-5197CriJun 3, 2024
    risk 0.59cvss 9.1epss 0.01

    There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned…

  • CVE-2022-1812CriJan 14, 2023
    risk 0.59cvss 9.8epss 0.31

    Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.

  • CVE-2021-37065CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Confidentiality or Availability impacted.

  • CVE-2021-22156CriAug 17, 2021
    risk 0.59cvss 9.0epss 0.02

    An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that…