VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,387)

page 28 of 170
  • CVE-2020-11269HigFeb 22, 2021
    risk 0.57cvss 8.8epss 0.00

    Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2020-13579HigFeb 4, 2021
    risk 0.57cvss 7.8epss 0.73

    An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. A specially crafted document can cause the document parser perform arithmetic that may overflow which can result in an…

  • CVE-2020-27906HigDec 8, 2020
    risk 0.57cvss 8.8epss 0.03

    Multiple integer overflows were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. A remote attacker may be able to cause unexpected application termination or heap corruption.

  • CVE-2020-28371CriNov 9, 2020
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in ReadyTalk Avian 1.2.0 before 2020-10-27. The FileOutputStream.write() method in FileOutputStream.java has a boundary check to prevent out-of-bounds memory read/write operations. However, an integer overflow leads to bypassing this check and achieving…

  • CVE-2020-15975HigNov 3, 2020
    risk 0.57cvss 8.8epss 0.01

    Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-15974HigNov 3, 2020
    risk 0.57cvss 8.8epss 0.01

    Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.

  • CVE-2020-0264HigSep 17, 2020
    risk 0.57cvss 8.8epss 0.01

    In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-116718596

  • CVE-2020-17396HigAug 25, 2020
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists…

  • CVE-2020-0240HigAug 11, 2020
    risk 0.57cvss 8.8epss 0.02

    In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-10929HigJul 28, 2020
    risk 0.57cvss 8.8epss 0.02

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string table file…

  • CVE-2020-6523HigJul 22, 2020
    risk 0.57cvss 8.8epss 0.03

    Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-12371HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.01

    An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR <…

  • CVE-2020-0194HigJun 11, 2020
    risk 0.57cvss 8.8epss 0.01

    In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-6094HigMay 6, 2020
    risk 0.57cvss 8.8epss 0.04

    An exploitable code execution vulnerability exists in the TIFF fillinraster function of the igcore19d.dll library of Accusoft ImageGear 19.4, 19.5 and 19.6. A specially crafted TIFF file can cause an out-of-bounds write, resulting in remote code execution. An attacker can…

  • CVE-2019-20788CriApr 23, 2020
    risk 0.57cvss 9.8epss 0.02

    libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.

  • CVE-2019-20787CriApr 22, 2020
    risk 0.57cvss 9.8epss 0.02

    Teeworlds before 0.7.4 has an integer overflow when computing a tilemap size.

  • CVE-2019-13203HigMar 13, 2020
    risk 0.57cvss 8.8epss 0.02

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by an integer overflow vulnerability in the arg3 parameter of several functionalities of the web application that would allow an authenticated attacker to perform a Denial of Service attack,…

  • CVE-2015-8751HigFeb 17, 2020
    risk 0.57cvss 8.8epss 0.03

    Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.

  • CVE-2020-6381HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2015-4042CriJan 24, 2020
    risk 0.57cvss 9.8epss 0.02

    Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings.