VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,583)

page 44 of 180
  • CVE-2026-18308HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18306HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18305HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18304HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18301HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18300HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-47940HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-65814HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-64911HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-64903HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-64898HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-63532HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-62751HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62735HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

  • CVE-2026-61937HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

  • CVE-2026-59127HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58641HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-70628HigAug 6, 2026
    risk 0.51cvss 7.8epss 0.00

    FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the…

  • CVE-2026-43627HigAug 6, 2026
    risk 0.51cvss 7.8epss 0.00

    llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger…

  • CVE-2026-71261HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chunk, a stage-1 capacity estimate truncates the 64-bit W64 chunk sizeInBytes to size_t before dividing by DRWAV_CUE_POINT_BYTES; on…