CWE-190
Integer Overflow or Wraparound
Description
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,398)
page 35 of 170| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-33022 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption while allocating memory in HGSL driver. | ||
| CVE-2024-23372 | Hig | 0.55 | 8.4 | 0.00 | Jul 1, 2024 | Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size. | ||
| CVE-2024-21470 | Hig | 0.55 | 8.4 | 0.00 | Apr 1, 2024 | Memory corruption while allocating memory for graphics. | ||
| CVE-2023-33022 | Hig | 0.55 | 8.4 | 0.00 | Dec 5, 2023 | Memory corruption in HLOS while invoking IOCTL calls from user-space. | ||
| CVE-2023-28537 | Hig | 0.55 | 8.4 | 0.00 | Aug 8, 2023 | Memory corruption while allocating memory in COmxApeDec module in Audio. | ||
| CVE-2023-22666 | Hig | 0.55 | 8.4 | 0.00 | Aug 8, 2023 | Memory Corruption in Audio while playing amrwbplus clips with modified content. | ||
| CVE-2023-22667 | Hig | 0.55 | 8.4 | 0.00 | Jul 4, 2023 | Memory Corruption in Audio while allocating the ion buffer during the music playback. | ||
| CVE-2023-21630 | Hig | 0.55 | 8.4 | 0.00 | Apr 13, 2023 | Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal. | ||
| CVE-2022-40532 | Hig | 0.55 | 8.4 | 0.00 | Apr 13, 2023 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | ||
| CVE-2022-33282 | Hig | 0.55 | 8.4 | 0.00 | Apr 13, 2023 | Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback. | ||
| CVE-2022-40530 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase. | ||
| CVE-2022-25656 | Hig | 0.55 | 8.4 | 0.00 | Sep 16, 2022 | Possible integer overflow and memory corruption due to improper validation of buffer size sent to write to console when computing the payload size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2022-22089 | Hig | 0.55 | 8.4 | 0.00 | Sep 16, 2022 | Memory corruption in audio while playing record due to improper list handling in two threads in Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2022-22081 | Hig | 0.55 | 8.4 | 0.00 | Sep 16, 2022 | Memory corruption in audio module due to integer overflow in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2022-22074 | Hig | 0.55 | 8.4 | 0.00 | Sep 16, 2022 | Memory Corruption during wma file playback due to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2021-35074 | Hig | 0.55 | 8.4 | 0.00 | Feb 11, 2022 | Possible integer overflow due to improper fragment datatype while calculating number of fragments in a request message in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2021-30274 | Hig | 0.55 | 8.4 | 0.00 | Jan 3, 2022 | Possible integer overflow in access control initialization interface due to lack and size and address validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired… | ||
| CVE-2021-1912 | Hig | 0.55 | 8.4 | 0.00 | Nov 12, 2021 | Possible integer overflow can occur due to improper length check while calculating count and grace period in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2021-1949 | Hig | 0.55 | 8.4 | 0.00 | Oct 20, 2021 | Possible integer overflow due to improper check of batch count value while sanitizer is enabled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables | ||
| CVE-2021-1913 | Hig | 0.55 | 8.4 | 0.00 | Oct 20, 2021 | Possible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking |
- risk 0.55cvss 8.4epss 0.00
Memory corruption while allocating memory in HGSL driver.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while allocating memory for graphics.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in HLOS while invoking IOCTL calls from user-space.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while allocating memory in COmxApeDec module in Audio.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Audio while playing amrwbplus clips with modified content.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Audio while allocating the ion buffer during the music playback.
- risk 0.55cvss 8.4epss 0.00
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
- risk 0.55cvss 8.4epss 0.00
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
- risk 0.55cvss 8.4epss 0.00
Possible integer overflow and memory corruption due to improper validation of buffer size sent to write to console when computing the payload size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.55cvss 8.4epss 0.00
Memory corruption in audio while playing record due to improper list handling in two threads in Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables
- risk 0.55cvss 8.4epss 0.00
Memory corruption in audio module due to integer overflow in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables
- risk 0.55cvss 8.4epss 0.00
Memory Corruption during wma file playback due to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.55cvss 8.4epss 0.00
Possible integer overflow due to improper fragment datatype while calculating number of fragments in a request message in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.55cvss 8.4epss 0.00
Possible integer overflow in access control initialization interface due to lack and size and address validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired…
- risk 0.55cvss 8.4epss 0.00
Possible integer overflow can occur due to improper length check while calculating count and grace period in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.55cvss 8.4epss 0.00
Possible integer overflow due to improper check of batch count value while sanitizer is enabled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables
- risk 0.55cvss 8.4epss 0.00
Possible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking