VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,583)

page 24 of 180
  • CVE-2025-20710HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418785;…

  • CVE-2025-10892HigSep 24, 2025
    risk 0.57cvss 8.8epss 0.00

    Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-10533HigSep 16, 2025
    risk 0.57cvss 8.8epss 0.01

    Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

  • CVE-2025-54106HigSep 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-30405CriAug 7, 2025
    risk 0.57cvss 9.8epss 0.01

    An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their allocated memory area, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit…

  • CVE-2025-30404CriAug 7, 2025
    risk 0.57cvss 9.8epss 0.01

    An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit d158236b1dc84539c1b16843bc74054c9dcba006.

  • CVE-2025-47998HigJul 8, 2025
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-5478HigJun 21, 2025
    risk 0.57cvss 8.8epss 0.00

    Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-AX8500 devices. Authentication is not required to exploit this…

  • CVE-2025-22039HigApr 16, 2025
    risk 0.57cvss 8.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was originally typed as int and used in an unchecked addition, which could overflow and bypass the existing bounds check in both…

  • CVE-2025-21369HigFeb 11, 2025
    risk 0.57cvss 8.8epss 0.02

    Microsoft Digest Authentication Remote Code Execution Vulnerability

  • CVE-2025-21244HigJan 14, 2025
    risk 0.57cvss 8.8epss 0.02

    Windows Telephony Service Remote Code Execution Vulnerability

  • CVE-2025-21243HigJan 14, 2025
    risk 0.57cvss 8.8epss 0.02

    Windows Telephony Service Remote Code Execution Vulnerability

  • CVE-2024-50944CriDec 27, 2024
    risk 0.57cvss 9.8epss 0.01

    Integer overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shopping cart functionality. The issue lies in the quantity parameter in the CartController's AddToCart method.

  • CVE-2024-49085HigDec 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-36671CriNov 29, 2024
    risk 0.57cvss 9.8epss 0.01

    nodemcu before v3.0.0-release_20240225 was discovered to contain an integer overflow via the getnum function at /modules/struct.c.

  • CVE-2024-7025HigNov 27, 2024
    risk 0.57cvss 8.8epss 0.01

    Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2018-9472HigNov 20, 2024
    risk 0.57cvss 8.8epss 0.00

    In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-43635HigNov 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Telephony Service Remote Code Execution Vulnerability

  • CVE-2024-43628HigNov 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Telephony Service Remote Code Execution Vulnerability

  • CVE-2024-9123HigSep 25, 2024
    risk 0.57cvss 8.8epss 0.00

    Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)