VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,387)

page 24 of 170
  • CVE-2024-28942HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-28936HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-28931HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-28929HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-21450HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-21444HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-21441HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-27304CriMar 6, 2024
    risk 0.57cvss 9.8epss 0.01

    pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the…

  • CVE-2024-23605HigFeb 26, 2024
    risk 0.57cvss 8.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2024-23496HigFeb 26, 2024
    risk 0.57cvss 8.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2024-21836HigFeb 26, 2024
    risk 0.57cvss 8.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2024-21825HigFeb 26, 2024
    risk 0.57cvss 8.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2024-21420HigFeb 13, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-21372HigFeb 13, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows OLE Remote Code Execution Vulnerability

  • CVE-2024-21350HigFeb 13, 2024
    risk 0.57cvss 8.8epss 0.01

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2023-47994HigJan 9, 2024
    risk 0.57cvss 8.8epss 0.01

    An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run arbitrary code.

  • CVE-2023-47992HigJan 9, 2024
    risk 0.57cvss 8.8epss 0.01

    An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or run arbitrary code.

  • CVE-2024-22051CriJan 4, 2024
    risk 0.57cvss 9.8epss 0.01

    CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing…

  • CVE-2023-5849HigNov 1, 2023
    risk 0.57cvss 8.8epss 0.01

    Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-42295HigOct 23, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_rle_image function of file bifs/unquantize.c