CWE-190
Integer Overflow or Wraparound
Description
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,583)
page 18 of 180| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-12293 | Hig | 0.61 | 8.8 | 0.10 | Jun 19, 2018 | The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer… | ||
| CVE-2026-9621 | — | Cri | 0.60 | — | 0.00 | Sep 1, 2026 | A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover | |
| CVE-2026-19313 | Cri | 0.60 | — | 0.00 | Aug 28, 2026 | An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | ||
| CVE-2026-16416 | Cri | 0.60 | 9.3 | 0.00 | Jul 21, 2026 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High) | ||
| CVE-2024-38144 | Hig | 0.60 | 8.8 | 0.32 | Aug 13, 2024 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2023-33032 | Cri | 0.60 | 9.3 | 0.00 | Jan 2, 2024 | Memory corruption in TZ Secure OS while requesting a memory allocation from TA region. | ||
| CVE-2022-33269 | Cri | 0.60 | 9.3 | 0.00 | Apr 13, 2023 | Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment. | ||
| CVE-2022-33219 | Cri | 0.60 | 9.3 | 0.00 | Jan 9, 2023 | Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer. | ||
| CVE-2022-28615 | Cri | 0.60 | 9.1 | 0.06 | Jun 9, 2022 | Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua… | ||
| CVE-2021-30275 | Cri | 0.60 | 9.3 | 0.00 | Jan 3, 2022 | Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired… | ||
| CVE-2016-2177 | Cri | 0.60 | 9.8 | 0.45 | Jun 20, 2016 | OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc… | ||
| CVE-2008-1083 | Hig | 0.60 | 8.1 | 0.57 | Apr 8, 2008 | Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers… | ||
| CVE-2026-51536 | Cri | 0.59 | 9.1 | 0.00 | Jul 13, 2026 | In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream length calculated as an int is passed to a downstream function that expects an… | ||
| CVE-2025-3500 | Cri | 0.59 | 9.0 | 0.00 | Dec 1, 2025 | Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3. | ||
| CVE-2025-7458 | Cri | 0.59 | 9.1 | 0.00 | Jul 29, 2025 | An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT… | ||
| CVE-2024-53146 | Cri | 0.59 | 9.1 | 0.01 | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding into several steps so… | ||
| CVE-2024-5197 | Cri | 0.59 | 9.1 | 0.01 | Jun 3, 2024 | There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned… | ||
| CVE-2022-1812 | Cri | 0.59 | 9.8 | 0.31 | Jan 14, 2023 | Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10. | ||
| CVE-2021-37065 | Cri | 0.59 | 9.1 | 0.01 | Dec 7, 2021 | There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Confidentiality or Availability impacted. | ||
| CVE-2021-22156 | Cri | 0.59 | 9.0 | 0.02 | Aug 17, 2021 | An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that… |
- risk 0.61cvss 8.8epss 0.10
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer…
- risk 0.60cvss —epss 0.00
A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover
- risk 0.60cvss —epss 0.00
An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
- risk 0.60cvss 9.3epss 0.00
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
- risk 0.60cvss 8.8epss 0.32
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
- risk 0.60cvss 9.3epss 0.00
Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.
- risk 0.60cvss 9.3epss 0.00
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer.
- risk 0.60cvss 9.1epss 0.06
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua…
- risk 0.60cvss 9.3epss 0.00
Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired…
- risk 0.60cvss 9.8epss 0.45
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc…
- risk 0.60cvss 8.1epss 0.57
Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers…
- risk 0.59cvss 9.1epss 0.00
In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream length calculated as an int is passed to a downstream function that expects an…
- risk 0.59cvss 9.0epss 0.00
Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.
- risk 0.59cvss 9.1epss 0.00
An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT…
- risk 0.59cvss 9.1epss 0.01
In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding into several steps so…
- risk 0.59cvss 9.1epss 0.01
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned…
- risk 0.59cvss 9.8epss 0.31
Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.
- risk 0.59cvss 9.1epss 0.01
There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Confidentiality or Availability impacted.
- risk 0.59cvss 9.0epss 0.02
An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that…