VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,583)

page 30 of 180
  • CVE-2020-10929HigJul 28, 2020
    risk 0.57cvss 8.8epss 0.02

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string table file…

  • CVE-2020-6523HigJul 22, 2020
    risk 0.57cvss 8.8epss 0.03

    Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-12371HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.01

    An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR <…

  • CVE-2020-0194HigJun 11, 2020
    risk 0.57cvss 8.8epss 0.01

    In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-6094HigMay 6, 2020
    risk 0.57cvss 8.8epss 0.04

    An exploitable code execution vulnerability exists in the TIFF fillinraster function of the igcore19d.dll library of Accusoft ImageGear 19.4, 19.5 and 19.6. A specially crafted TIFF file can cause an out-of-bounds write, resulting in remote code execution. An attacker can…

  • CVE-2019-20788CriApr 23, 2020
    risk 0.57cvss 9.8epss 0.03

    libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.

  • CVE-2019-20787CriApr 22, 2020
    risk 0.57cvss 9.8epss 0.02

    Teeworlds before 0.7.4 has an integer overflow when computing a tilemap size.

  • CVE-2019-13203HigMar 13, 2020
    risk 0.57cvss 8.8epss 0.02

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by an integer overflow vulnerability in the arg3 parameter of several functionalities of the web application that would allow an authenticated attacker to perform a Denial of Service attack,…

  • CVE-2015-8751HigFeb 17, 2020
    risk 0.57cvss 8.8epss 0.03

    Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.

  • CVE-2020-6381HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2015-4042CriJan 24, 2020
    risk 0.57cvss 9.8epss 0.02

    Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings.

  • CVE-2019-20205HigJan 2, 2020
    risk 0.57cvss 8.8epss 0.01

    libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.

  • CVE-2019-13736HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2011-3631HigNov 26, 2019
    risk 0.57cvss 8.8epss 0.03

    Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and…

  • CVE-2019-5854HigNov 25, 2019
    risk 0.57cvss 8.8epss 0.01

    Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2019-5087HigNov 21, 2019
    risk 0.57cvss 8.8epss 0.04

    An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An integer overflow can occur while calculating the row's allocation size, that could be exploited to corrupt memory and eventually…

  • CVE-2019-5086HigNov 21, 2019
    risk 0.57cvss 8.8epss 0.03

    An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary…

  • CVE-2019-9405HigSep 27, 2019
    risk 0.57cvss 8.8epss 0.01

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112890225

  • CVE-2019-9357HigSep 27, 2019
    risk 0.57cvss 8.8epss 0.01

    In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112662995

  • CVE-2019-9310HigSep 27, 2019
    risk 0.57cvss 8.8epss 0.01

    In libFDK, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112891546