CWE-190
Integer Overflow or Wraparound
Description
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,583)
page 7 of 180| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23298 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when allocating the underlying bitmap buffer. A malicious application could call the API method with… | ||
| CVE-2023-26065 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2023 | Certain Lexmark devices through 2023-02-19 have an Integer Overflow. | ||
| CVE-2023-28501 | Cri | 0.64 | 9.8 | 0.01 | Mar 29, 2023 | Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user. | ||
| CVE-2022-20532 | Cri | 0.64 | 9.8 | 0.00 | Mar 24, 2023 | In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-0754 | Cri | 0.64 | 9.8 | 0.03 | Feb 23, 2023 | The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code. | ||
| CVE-2023-23462 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2023 | Libpeconv – integer overflow, before commit 75b1565 (30/11/2022). | ||
| CVE-2023-21803 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2023 | Windows iSCSI Discovery Service Remote Code Execution Vulnerability | ||
| CVE-2022-2329 | Cri | 0.64 | 9.8 | 0.02 | Feb 1, 2023 | A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Products: IGSS Data Server -… | ||
| CVE-2022-28331 | Cri | 0.64 | 9.8 | 0.02 | Jan 31, 2023 | On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow. | ||
| CVE-2022-24963 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2023 | Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0. | ||
| CVE-2022-3515 | Cri | 0.64 | 9.8 | 0.02 | Jan 12, 2023 | A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment. | ||
| CVE-2022-47629 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2022 | Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser. | ||
| CVE-2022-25748 | Cri | 0.64 | 9.8 | 0.00 | Oct 19, 2022 | Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,… | ||
| CVE-2022-36934 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2022 | An integer overflow in WhatsApp could result in remote code execution in an established video call. | ||
| CVE-2022-31789 | Cri | 0.64 | 9.8 | 0.02 | Sep 6, 2022 | An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code by sending a malicious request to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10,… | ||
| CVE-2022-25651 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Memory corruption in bluetooth host due to integer overflow while processing BT HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music | ||
| CVE-2022-26775 | Cri | 0.64 | 9.8 | 0.02 | May 26, 2022 | An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4. An attacker may be able to cause unexpected application termination or arbitrary code execution. | ||
| CVE-2022-26711 | Cri | 0.64 | 9.8 | 0.04 | May 26, 2022 | An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or… | ||
| CVE-2022-23884 | Cri | 0.64 | 9.8 | 0.03 | Mar 28, 2022 | Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer). | ||
| CVE-2022-26495 | Cri | 0.64 | 9.8 | 0.03 | Mar 6, 2022 | In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists… |
- risk 0.64cvss 9.8epss 0.01
The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when allocating the underlying bitmap buffer. A malicious application could call the API method with…
- risk 0.64cvss 9.8epss 0.01
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
- risk 0.64cvss 9.8epss 0.01
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.
- risk 0.64cvss 9.8epss 0.00
In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.64cvss 9.8epss 0.03
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).
- risk 0.64cvss 9.8epss 0.02
Windows iSCSI Discovery Service Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Products: IGSS Data Server -…
- risk 0.64cvss 9.8epss 0.02
On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.
- risk 0.64cvss 9.8epss 0.01
Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.
- risk 0.64cvss 9.8epss 0.02
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
- risk 0.64cvss 9.8epss 0.02
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
- risk 0.64cvss 9.8epss 0.00
Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…
- risk 0.64cvss 9.8epss 0.02
An integer overflow in WhatsApp could result in remote code execution in an established video call.
- risk 0.64cvss 9.8epss 0.02
An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code by sending a malicious request to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10,…
- risk 0.64cvss 9.8epss 0.01
Memory corruption in bluetooth host due to integer overflow while processing BT HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
- risk 0.64cvss 9.8epss 0.02
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4. An attacker may be able to cause unexpected application termination or arbitrary code execution.
- risk 0.64cvss 9.8epss 0.04
An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or…
- risk 0.64cvss 9.8epss 0.03
Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer).
- risk 0.64cvss 9.8epss 0.03
In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists…