VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,398)

page 49 of 170
  • CVE-2023-2914HigAug 17, 2023
    risk 0.51cvss 7.5epss 0.40

    The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a read access violation occurs and terminates the process. A…

  • CVE-2023-36866HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2023-35372HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2022-33065HigJul 18, 2023
    risk 0.51cvss 7.8epss 0.00

    Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header in src/mat4.c in Libsndfile, allows an attacker to cause Denial of Service or other unspecified impacts.

  • CVE-2023-21241HigJul 13, 2023
    risk 0.51cvss 7.8epss 0.00

    In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35312HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability

  • CVE-2023-32051HigJul 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Raw Image Extension Remote Code Execution Vulnerability

  • CVE-2023-25004HigJun 27, 2023
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution.

  • CVE-2023-28295HigJun 17, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Publisher Remote Code Execution Vulnerability

  • CVE-2023-2603HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.01

    A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.

  • CVE-2023-2610HigMay 9, 2023
    risk 0.51cvss 7.8epss 0.00

    Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.

  • CVE-2023-27937HigMay 8, 2023
    risk 0.51cvss 7.8epss 0.00

    An integer overflow was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Big Sur 11.7.5, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. Parsing a maliciously crafted plist may lead to an unexpected app…

  • CVE-2021-0885HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgeSyncPrimOpTake of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2021-0884HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgePhysmemImportSparseDmaBuf of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed.…

  • CVE-2021-0883HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgeCacheOpQueue of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2021-0882HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgeRGXKickSync of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2021-0881HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgeRGXKickCDM of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2021-0880HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgeRGXKickTA3D of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2021-0879HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgeRGXTDMSubmitTransfer of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2021-0878HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgeServerSyncGetStatus of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User…