VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,398)

page 51 of 170
  • CVE-2023-21765HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Print Spooler Elevation of Privilege Vulnerability

  • CVE-2023-21754HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-21730HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Cryptographic Services Elevation of Privilege Vulnerability

  • CVE-2023-21561HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Microsoft Cryptographic Services Elevation of Privilege Vulnerability

  • CVE-2022-47660HigJan 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is has an integer overflow in isomedia/isom_write.c

  • CVE-2022-20598HigDec 16, 2022
    risk 0.51cvss 7.8epss 0.00

    In sec_media_protect of media.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege of secure mode MFC Core with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20597HigDec 16, 2022
    risk 0.51cvss 7.8epss 0.00

    In ppmpu_set of ppmpu.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID:…

  • CVE-2022-42805HigDec 15, 2022
    risk 0.51cvss 7.8epss 0.00

    An integer overflow was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2022-41325HigDec 6, 2022
    risk 0.51cvss 7.8epss 0.01

    An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.

  • CVE-2022-42533HigNov 17, 2022
    risk 0.51cvss 7.8epss 0.00

    In shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0951HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In DevmemIntHeapAcquire of TBD, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-0871HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In PVRSRVBridgePMRPDumpSymbolicAddr of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2022-24107HigAug 30, 2022
    risk 0.51cvss 7.8epss 0.00

    Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.

  • CVE-2022-24106HigAug 30, 2022
    risk 0.51cvss 7.8epss 0.00

    In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.

  • CVE-2022-38784HigAug 30, 2022
    risk 0.51cvss 7.8epss 0.01

    Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the…

  • CVE-2022-38171HigAug 22, 2022
    risk 0.51cvss 7.8epss 0.00

    Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the…

  • CVE-2022-20383HigAug 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In AllocateInternalBuffers of g3aa_buffer_allocator.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-32543HigAug 5, 2022
    risk 0.51cvss 7.8epss 0.00

    An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2022-29886HigAug 5, 2022
    risk 0.51cvss 7.8epss 0.00

    An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2022-2122HigJul 19, 2022
    risk 0.51cvss 7.8epss 0.00

    DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities,…