VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,387)

page 23 of 170
  • CVE-2025-21243HigJan 14, 2025
    risk 0.57cvss 8.8epss 0.02

    Windows Telephony Service Remote Code Execution Vulnerability

  • CVE-2024-50944CriDec 27, 2024
    risk 0.57cvss 9.8epss 0.01

    Integer overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shopping cart functionality. The issue lies in the quantity parameter in the CartController's AddToCart method.

  • CVE-2024-49085HigDec 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-36671CriNov 29, 2024
    risk 0.57cvss 9.8epss 0.01

    nodemcu before v3.0.0-release_20240225 was discovered to contain an integer overflow via the getnum function at /modules/struct.c.

  • CVE-2024-7025HigNov 27, 2024
    risk 0.57cvss 8.8epss 0.01

    Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2018-9472HigNov 20, 2024
    risk 0.57cvss 8.8epss 0.00

    In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-43635HigNov 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Telephony Service Remote Code Execution Vulnerability

  • CVE-2024-43628HigNov 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Telephony Service Remote Code Execution Vulnerability

  • CVE-2024-9123HigSep 25, 2024
    risk 0.57cvss 8.8epss 0.00

    Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-44087HigSep 10, 2024
    risk 0.57cvss 8.6epss 0.11

    A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager V6.2 (All versions < V6.2 Upd3). Affected applications do not properly validate certain fields in…

  • CVE-2024-38128HigAug 13, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-37336HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.02

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

  • CVE-2024-37323HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.02

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

  • CVE-2024-21428HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.02

    SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

  • CVE-2024-30064HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-27833HigJun 10, 2024
    risk 0.57cvss 8.8epss 0.01

    An integer overflow was addressed with improved input validation. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, tvOS 17.5, visionOS 1.2. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2023-40475HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.02

    GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack…

  • CVE-2023-40474HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.02

    GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack…

  • CVE-2023-38104HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack…

  • CVE-2023-38103HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.02

    GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack…