VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,386)

page 7 of 170
  • CVE-2022-47629CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.02

    Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.

  • CVE-2022-25748CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…

  • CVE-2022-36934CriSep 22, 2022
    risk 0.64cvss 9.8epss 0.02

    An integer overflow in WhatsApp could result in remote code execution in an established video call.

  • CVE-2022-31789CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.02

    An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code by sending a malicious request to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10,…

  • CVE-2022-25651CriJun 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Memory corruption in bluetooth host due to integer overflow while processing BT HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2022-26775CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.02

    An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4. An attacker may be able to cause unexpected application termination or arbitrary code execution.

  • CVE-2022-26711CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.04

    An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or…

  • CVE-2022-23884CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.03

    Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer).

  • CVE-2022-26495CriMar 6, 2022
    risk 0.64cvss 9.8epss 0.03

    In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists…

  • CVE-2021-22480CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.

  • CVE-2022-25330CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.05

    Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution.

  • CVE-2022-24310CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.02

    A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Product: Interactive Graphical…

  • CVE-2021-30636CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.01

    In MediaTek LinkIt SDK before 4.6.1, there is a possible memory corruption due to an integer overflow during mishandled memory allocation by pvPortCalloc and pvPortRealloc.

  • CVE-2021-26706CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in lib_mem.c in Micrium uC/OS uC/LIB 1.38.x and 1.39.00. The following memory allocation functions do not check for integer overflow when allocating a pool whose size exceeds the address space: Mem_PoolCreate, Mem_DynPoolCreate, and Mem_DynPoolCreateHW.…

  • CVE-2021-39993CriJan 10, 2022
    risk 0.64cvss 9.8epss 0.01

    There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-37095CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remote denial of service and potential remote code execution.

  • CVE-2020-18684CriSep 30, 2021
    risk 0.64cvss 9.8epss 0.01

    Floodlight through 1.2 has an integer overflow in checkFlow in StaticFlowEntryPusherResource.java via priority or port number.

  • CVE-2021-21832CriAug 17, 2021
    risk 0.64cvss 9.8epss 0.01

    A memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-22388CriAug 2, 2021
    risk 0.64cvss 9.8epss 0.01

    There is an Integer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.

  • CVE-2021-20110CriJul 19, 2021
    risk 0.64cvss 9.8epss 0.07

    Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on…