CWE-190
Integer Overflow or Wraparound
Description
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,398)
page 70 of 170| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-33024 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length. | ||
| CVE-2024-36968 | Hig | 0.49 | 7.6 | 0.00 | Jun 8, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init() l2cap_le_flowctl_init() can cause both div-by-zero and an integer overflow since hdev->le_mtu may not fall in the valid range. Move MTU from… | ||
| CVE-2023-49441 | Hig | 0.49 | 7.5 | 0.01 | Jun 6, 2024 | dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query. | ||
| CVE-2023-41185 | Hig | 0.49 | 7.5 | 0.01 | May 3, 2024 | Unified Automation UaGateway Certificate Parsing Integer Overflow Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is not required to… | ||
| CVE-2024-23531 | Hig | 0.49 | 7.5 | 0.02 | Apr 19, 2024 | An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory. | ||
| CVE-2024-31031 | Hig | 0.49 | 7.5 | 0.01 | Apr 17, 2024 | An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow. | ||
| CVE-2024-21454 | Hig | 0.49 | 7.5 | 0.00 | Apr 1, 2024 | Transient DOS while decoding the ToBeSignedMessage in Automotive Telematics. | ||
| CVE-2021-47109 | Hig | 0.49 | 7.5 | 0.01 | Mar 15, 2024 | In the Linux kernel, the following vulnerability has been resolved: neighbour: allow NUD_NOARP entries to be forced GCed IFF_POINTOPOINT interfaces use NUD_NOARP entries for IPv6. It's possible to fill up the neighbour table with enough entries that it will overflow for valid… | ||
| CVE-2023-24609 | Hig | 0.49 | 7.5 | 0.01 | Dec 22, 2023 | Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in the TLS 1.3 server. An attacked device calculates an SHA-2 hash over at least 65 KB (in RAM). With a large number of crafted TLS… | ||
| CVE-2023-43826 | Hig | 0.49 | 7.5 | 0.01 | Dec 19, 2023 | Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a malicious or compromised VNC server, specially-crafted data could result in memory corruption, possibly allowing… | ||
| CVE-2023-28588 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Bluetooth Host while rfc slot allocation. | ||
| CVE-2023-4398 | Hig | 0.49 | 7.5 | 0.01 | Nov 28, 2023 | An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37,… | ||
| CVE-2023-36395 | Hig | 0.49 | 7.5 | 0.02 | Nov 14, 2023 | Windows Deployment Services Denial of Service Vulnerability | ||
| CVE-2023-5173 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2023 | In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a… | ||
| CVE-2023-28831 | Hig | 0.49 | 7.5 | 0.01 | Sep 12, 2023 | The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation. This could allow an unauthenticated remote attacker to create a denial of… | ||
| CVE-2020-21699 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests. | ||
| CVE-2023-39125 | Hig | 0.49 | 7.5 | 0.01 | Aug 18, 2023 | NTSC-CRT 2.2.1 has an integer overflow and out-of-bounds write in loadBMP in bmp_rw.c because a file's width, height, and BPP are not validated. NOTE: the vendor's perspective is "this main application was not intended to be a well tested program, it's just something to… | ||
| CVE-2023-35383 | Hig | 0.49 | 7.5 | 0.03 | Aug 8, 2023 | Microsoft Message Queuing Information Disclosure Vulnerability | ||
| CVE-2023-3107 | Hig | 0.49 | 7.5 | 0.01 | Aug 1, 2023 | A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service. | ||
| CVE-2023-20693 | Hig | 0.49 | 7.5 | 0.00 | Jul 4, 2023 | In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664711; Issue ID: ALPS07664711. |
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.
- risk 0.49cvss 7.6epss 0.00
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init() l2cap_le_flowctl_init() can cause both div-by-zero and an integer overflow since hdev->le_mtu may not fall in the valid range. Move MTU from…
- risk 0.49cvss 7.5epss 0.01
dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.
- risk 0.49cvss 7.5epss 0.01
Unified Automation UaGateway Certificate Parsing Integer Overflow Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is not required to…
- risk 0.49cvss 7.5epss 0.02
An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory.
- risk 0.49cvss 7.5epss 0.01
An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while decoding the ToBeSignedMessage in Automotive Telematics.
- risk 0.49cvss 7.5epss 0.01
In the Linux kernel, the following vulnerability has been resolved: neighbour: allow NUD_NOARP entries to be forced GCed IFF_POINTOPOINT interfaces use NUD_NOARP entries for IPv6. It's possible to fill up the neighbour table with enough entries that it will overflow for valid…
- risk 0.49cvss 7.5epss 0.01
Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in the TLS 1.3 server. An attacked device calculates an SHA-2 hash over at least 65 KB (in RAM). With a large number of crafted TLS…
- risk 0.49cvss 7.5epss 0.01
Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a malicious or compromised VNC server, specially-crafted data could result in memory corruption, possibly allowing…
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Bluetooth Host while rfc slot allocation.
- risk 0.49cvss 7.5epss 0.01
An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37,…
- risk 0.49cvss 7.5epss 0.02
Windows Deployment Services Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a…
- risk 0.49cvss 7.5epss 0.01
The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation. This could allow an unauthenticated remote attacker to create a denial of…
- risk 0.49cvss 7.5epss 0.01
The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests.
- risk 0.49cvss 7.5epss 0.01
NTSC-CRT 2.2.1 has an integer overflow and out-of-bounds write in loadBMP in bmp_rw.c because a file's width, height, and BPP are not validated. NOTE: the vendor's perspective is "this main application was not intended to be a well tested program, it's just something to…
- risk 0.49cvss 7.5epss 0.03
Microsoft Message Queuing Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.01
A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.
- risk 0.49cvss 7.5epss 0.00
In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664711; Issue ID: ALPS07664711.