VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,583)

page 21 of 180
  • CVE-2010-2753HigJul 30, 2010
    risk 0.58cvss 8.8epss 0.07

    Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which…

  • CVE-2010-0130HigMay 13, 2010
    risk 0.58cvss 8.8epss 0.07

    Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via a crafted .dir (aka Director) file.

  • CVE-2010-0129HigMay 13, 2010
    risk 0.58cvss 8.8epss 0.06

    Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir (aka Director) file that triggers an array index error.

  • CVE-2026-11725HigSep 18, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

  • CVE-2026-11378HigSep 18, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.

  • CVE-2026-65391HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.00

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.

  • CVE-2026-65390HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.00

    An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.

  • CVE-2026-16174HigSep 10, 2026
    risk 0.57cvss —epss 0.00

    Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to…

  • CVE-2026-77486HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-72986HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.

  • CVE-2026-71336HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.

  • CVE-2026-70351HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69742HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69499HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69266HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.00

    Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-67384HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

  • CVE-2026-85438CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.00

    MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. Attackers can supply crafted payloads with…

  • CVE-2026-82908HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer…

  • CVE-2026-79223HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.00

    Integer overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted file. (Chromium security severity: Low)

  • CVE-2026-79215HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.00

    Integer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)