VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,583)

page 37 of 180
  • CVE-2023-22666HigAug 8, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory Corruption in Audio while playing amrwbplus clips with modified content.

  • CVE-2023-22667HigJul 4, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory Corruption in Audio while allocating the ion buffer during the music playback.

  • CVE-2023-21630HigApr 13, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.

  • CVE-2022-40532HigApr 13, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.

  • CVE-2022-33282HigApr 13, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback.

  • CVE-2022-40530HigMar 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.

  • CVE-2022-25656HigSep 16, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible integer overflow and memory corruption due to improper validation of buffer size sent to write to console when computing the payload size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2022-22089HigSep 16, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in audio while playing record due to improper list handling in two threads in Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2022-22081HigSep 16, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in audio module due to integer overflow in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2022-22074HigSep 16, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory Corruption during wma file playback due to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-35074HigFeb 11, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible integer overflow due to improper fragment datatype while calculating number of fragments in a request message in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-30274HigJan 3, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible integer overflow in access control initialization interface due to lack and size and address validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired…

  • CVE-2021-1912HigNov 12, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible integer overflow can occur due to improper length check while calculating count and grace period in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-1949HigOct 20, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible integer overflow due to improper check of batch count value while sanitizer is enabled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1913HigOct 20, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

  • CVE-2021-30260HigSep 17, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist configuration command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…

  • CVE-2020-11245HigApr 7, 2021
    risk 0.55cvss 8.4epss 0.00

    Unintended reads and writes by NS EL2 in access control driver due to lack of check of input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and…

  • CVE-2018-9363HigNov 6, 2018
    risk 0.55cvss 8.4epss 0.00

    In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-65853588…

  • CVE-2015-5621HigAug 19, 2015
    risk 0.55cvss 7.5epss 0.41

    The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code…

  • CVE-2012-1867HigJun 12, 2012
    risk 0.55cvss 8.4epss 0.01

    Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted TrueType font file…