VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (689)

page 26 of 35
  • CVE-2017-16663MedNov 8, 2017
    risk 0.36cvss 5.5epss 0.00

    In sam2p 0.49.4, there are integer overflows (with resultant heap-based buffer overflows) in input-bmp.ci in the function ReadImage, because "width * height" multiplications occur unsafely.

  • CVE-2017-15873MedOct 24, 2017
    risk 0.36cvss 5.5epss 0.00

    The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation.

  • CVE-2017-14861MedSep 29, 2017
    risk 0.36cvss 5.5epss 0.00

    There is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function of image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.

  • CVE-2015-1526MedSep 28, 2017
    risk 0.36cvss 5.5epss 0.00

    The media_server component in Android allows remote attackers to cause a denial of service via a crafted application.

  • CVE-2017-12797MedAug 29, 2017
    risk 0.36cvss 5.5epss 0.00

    Integer overflow in the INT123_parse_new_id3 function in the ID3 parser in mpg123 before 1.25.5 on 32-bit platforms allows remote attackers to cause a denial of service via a crafted file, which triggers a heap-based buffer overflow.

  • CVE-2017-7542MedJul 21, 2017
    risk 0.36cvss 5.5epss 0.00

    The ip6_find_1stfragopt function in net/ipv6/output_core.c in the Linux kernel through 4.12.3 allows local users to cause a denial of service (integer overflow and infinite loop) by leveraging the ability to open a raw socket.

  • CVE-2017-0691MedJul 6, 2017
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36724453.

  • CVE-2017-7982MedApr 20, 2017
    risk 0.36cvss 5.5epss 0.00

    Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.

  • CVE-2016-9557MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.00

    Integer overflow in jas_image.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (application crash) via a crafted file.

  • CVE-2016-9262MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.00

    Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.

  • CVE-2017-6839MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.06

    Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2017-6838MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.06

    Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2015-4645MedMar 17, 2017
    risk 0.36cvss 5.5epss 0.00

    Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.

  • CVE-2017-5898MedMar 15, 2017
    risk 0.36cvss 5.5epss 0.00

    Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit.

  • CVE-2017-6355MedMar 10, 2017
    risk 0.36cvss 5.5epss 0.00

    Integer overflow in the vrend_create_shader function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (process crash) via crafted pkt_length and offlen values, which trigger an out-of-bounds access.

  • CVE-2017-6312MedMar 10, 2017
    risk 0.36cvss 5.5epss 0.00

    Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.

  • CVE-2016-6522MedMar 7, 2017
    risk 0.36cvss 5.5epss 0.00

    Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of service (kernel panic) via a crafted mmap call, which triggers the new mapping to overlap with an existing mapping.

  • CVE-2017-5501MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.00

    Integer overflow in libjasper/jpc/jpc_tsfb.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2017-5499MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.00

    Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2016-9824MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.00

    Integer overflow in libswscale/x86/swscale.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.