VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,583)

page 36 of 180
  • CVE-2026-34963HigMay 11, 2026
    risk 0.55cvss 8.4epss 0.00

    barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithmetic on section VirtualAddress and size values allows undersized heap…

  • CVE-2026-37540HigMay 1, 2026
    risk 0.55cvss 8.4epss 0.00

    OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it performs multiplication of two attacker-controlled 16-bit values from the ELF header without overflow checking. On 32-bit embedded systems (STM32MP1, Zynq,…

  • CVE-2026-33471CriApr 22, 2026
    risk 0.55cvss 9.6epss 0.00

    nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterates `BitSet` indices and casts each `usize` index to `u16` (`slot as u16`) for slot lookup. Prior to version 1.3.0,…

  • CVE-2026-32845HigMar 23, 2026
    risk 0.55cvss 8.4epss 0.00

    cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating sparse accessors that allows attackers to trigger out-of-bounds reads by supplying crafted glTF/GLB input files with attacker-controlled size values. Attackers…

  • CVE-2026-0031HigMar 2, 2026
    risk 0.55cvss 8.4epss 0.00

    In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0028HigMar 2, 2026
    risk 0.55cvss 8.4epss 0.00

    In __pkvm_host_share_guest of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0861HigJan 14, 2026
    risk 0.55cvss 8.4epss 0.00

    Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have…

  • CVE-2024-52035HigJun 2, 2025
    risk 0.55cvss 8.4epss 0.00

    An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2025-22080HigApr 16, 2025
    risk 0.55cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Prevent integer overflow in hdr_first_de() The "de_off" and "used" variables come from the disk so they both need to check. The problem is that on 32bit systems if they're both greater than UINT_MAX…

  • CVE-2022-49451HigFeb 26, 2025
    risk 0.55cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix list protocols enumeration in the base protocol While enumerating protocols implemented by the SCMI platform using BASE_DISCOVER_LIST_PROTOCOLS, the number of returned protocols is…

  • CVE-2024-34733HigJan 28, 2025
    risk 0.55cvss 8.4epss 0.00

    In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-45555HigJan 6, 2025
    risk 0.55cvss 8.4epss 0.00

    Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image.

  • CVE-2024-42415HigOct 3, 2024
    risk 0.55cvss 8.4epss 0.00

    An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when…

  • CVE-2024-36474HigOct 3, 2024
    risk 0.55cvss 8.4epss 0.00

    An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A specially crafted file can result in an integer overflow when processing the directory from the file that…

  • CVE-2024-33035HigSep 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.

  • CVE-2024-33022HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while allocating memory in HGSL driver.

  • CVE-2024-23372HigJul 1, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.

  • CVE-2024-21470HigApr 1, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while allocating memory for graphics.

  • CVE-2023-33022HigDec 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in HLOS while invoking IOCTL calls from user-space.

  • CVE-2023-28537HigAug 8, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while allocating memory in COmxApeDec module in Audio.