VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,398)

page 50 of 170
  • CVE-2021-0876HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgePhysmemNewRamBackedLockedPMR of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed.…

  • CVE-2021-0875HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgeChangeSparseMem of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2021-0874HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgeDevicememHistorySparseChange of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed.…

  • CVE-2021-0873HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgeRGXKickRS of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2021-0872HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgeRGXKickVRDM of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2023-1900HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability within the Avira network protection feature allowed an attacker with local execution rights to cause an overflow. This could corrupt the data on the heap and lead to a denial-of-service situation. Issue was fixed with Endpointprotection.exe version 1.0.2303.633

  • CVE-2023-27913HigApr 14, 2023
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to cause an Integer Overflow. A malicious actor can leverage this vulnerability to cause a crash or read sensitive data, or execute arbitrary code in the context of the current process.

  • CVE-2023-28248HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-28237HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Remote Code Execution Vulnerability

  • CVE-2023-25903HigMar 28, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Dimension versions 3.4.7 (and earlier) is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2023-0179HigMar 27, 2023
    risk 0.51cvss 7.8epss 0.02

    A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.

  • CVE-2023-23417HigMar 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Partition Management Driver Elevation of Privilege Vulnerability

  • CVE-2023-23410HigMar 14, 2023
    risk 0.51cvss 7.8epss 0.08

    Windows HTTP.sys Elevation of Privilege Vulnerability

  • CVE-2022-25705HigMar 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response

  • CVE-2023-22436HigMar 10, 2023
    risk 0.51cvss 7.8epss 0.00

    The kernel subsystem function check_permission_for_set_tokenid within OpenHarmony-v3.1.5 and prior versions has an UAF vulnerability which local attackers can exploit this vulnerability to escalate the privilege to root.

  • CVE-2023-26242HigFeb 21, 2023
    risk 0.51cvss 7.8epss 0.00

    afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow.

  • CVE-2023-21802HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Media Remote Code Execution Vulnerability

  • CVE-2023-21704HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2022-33248HigFeb 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.

  • CVE-2023-21579HigJan 18, 2023
    risk 0.51cvss 7.8epss 0.05

    Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of…