VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,398)

page 38 of 170
  • CVE-2025-23016CriJan 10, 2025
    risk 0.53cvss 9.3epss 0.01

    FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

  • CVE-2024-51540HigDec 26, 2024
    risk 0.53cvss 8.1epss 0.00

    Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of ECS. An authenticated user with bucket or object-level access and the necessary privileges could potentially exploit this vulnerability to bypass retention…

  • CVE-2023-41056HigJan 10, 2024
    risk 0.53cvss 8.1epss 0.03

    Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.

  • CVE-2023-4949HigNov 10, 2023
    risk 0.53cvss 8.1epss 0.00

    An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation.

  • CVE-2023-37536HigOct 11, 2023
    risk 0.53cvss 8.2epss 0.01

    An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

  • CVE-2023-24949HigMay 9, 2023
    risk 0.53cvss 7.8epss 0.25

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-24908HigMar 14, 2023
    risk 0.53cvss 8.1epss 0.01

    Remote Procedure Call Runtime Remote Code Execution Vulnerability

  • CVE-2023-24869HigMar 14, 2023
    risk 0.53cvss 8.1epss 0.01

    Remote Procedure Call Runtime Remote Code Execution Vulnerability

  • CVE-2023-23405HigMar 14, 2023
    risk 0.53cvss 8.1epss 0.01

    Remote Procedure Call Runtime Remote Code Execution Vulnerability

  • CVE-2022-43974HigJan 9, 2023
    risk 0.53cvss 8.1epss 0.02

    MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13. A remote attacker might be able to send a crafted TLS Message to cause a buffer overflow and achieve remote code execution. This is fixed in 4.6.0.

  • CVE-2022-23484HigDec 9, 2022
    risk 0.53cvss 8.2epss 0.01

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. There are no known workarounds for this issue. Users…

  • CVE-2021-4206HigApr 29, 2022
    risk 0.53cvss 8.2epss 0.01

    A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash…

  • CVE-2021-26109HigDec 8, 2021
    risk 0.53cvss 8.1epss 0.02

    An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary code execution.

  • CVE-2021-29644HigOct 12, 2021
    risk 0.53cvss 8.1epss 0.03

    Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying OS.

  • CVE-2021-34372HigJun 22, 2021
    risk 0.53cvss 8.2epss 0.00

    Trusty (the trusted OS produced by NVIDIA for Jetson devices) driver contains a vulnerability in the NVIDIA OTE protocol message parsing code where an integer overflow in a malloc() size calculation leads to a buffer overflow on the heap, which might result in information…

  • CVE-2020-29238HigMar 10, 2021
    risk 0.53cvss 7.5epss 0.16

    An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.

  • CVE-2020-36242CriFeb 7, 2021
    risk 0.53cvss 9.1epss 0.07

    In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

  • CVE-2020-16040MedJan 8, 2021
    risk 0.53cvss 6.5epss 1.00

    Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-25693HigDec 3, 2020
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially crafted input file processed by CImg, which can lead to an impact to application availability or data integrity.

  • CVE-2020-6116HigSep 17, 2020
    risk 0.53cvss 7.8epss 0.28

    An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed colorspace, the application can miscalculate the size of a buffer when allocating…