VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,398)

page 71 of 170
  • CVE-2023-20691HigJul 4, 2023
    risk 0.49cvss 7.5epss 0.00

    In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664731; Issue ID: ALPS07664731.

  • CVE-2023-20690HigJul 4, 2023
    risk 0.49cvss 7.5epss 0.00

    In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664735; Issue ID: ALPS07664735.

  • CVE-2023-20689HigJul 4, 2023
    risk 0.49cvss 7.5epss 0.00

    In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664741; Issue ID: ALPS07664741.

  • CVE-2023-21193HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.00

    In VideoFrame of VideoFrame.h, there is a possible abort due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:…

  • CVE-2020-20335HigJun 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in Antirez Kilo before commit 7709a04ae8520c5b04d261616098cebf742f5a23 allows a remote attacker to cause a denial of service via the editorUpdateRow function in kilo.c.

  • CVE-2023-32307HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8599-x7rq-fr54), several other potential heap-over-flow and integer-overflow in…

  • CVE-2022-48480HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    Integer overflow vulnerability in some phones. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-30463HigApr 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Altran picoTCP through 1.7.0 allows memory corruption (and subsequent denial of service) because of an integer overflow in pico_ipv6_alloc when processing large ICMPv6 packets. This affects installations with Ethernet support in which a packet size greater than 65495 may occur.

  • CVE-2023-24537HigApr 6, 2023
    risk 0.49cvss 7.5epss 0.01

    Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow.

  • CVE-2023-0705HigFeb 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who had one a race condition to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2022-38725HigJan 23, 2023
    risk 0.49cvss 7.5epss 0.02

    An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0…

  • CVE-2023-21557HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

  • CVE-2022-20410HigOct 11, 2022
    risk 0.49cvss 7.5epss 0.01

    In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-2831HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption.

  • CVE-2022-36125HigAug 9, 2022
    risk 0.49cvss 7.5epss 0.01

    It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.

  • CVE-2022-31600HigJul 4, 2022
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmmCore, where a user with high privileges can chain another vulnerability to this vulnerability, causing an integer overflow, possibly leading to code execution, escalation of privileges, denial of service, compromised…

  • CVE-2022-28937HigMay 15, 2022
    risk 0.49cvss 7.5epss 0.01

    FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an invalid header, will cause normal nodes to stop producing new blocks and processing new clients' requests.

  • CVE-2022-28936HigMay 15, 2022
    risk 0.49cvss 7.5epss 0.01

    FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow and cause a Denial of Service (DoS) via an unusually large viewchange message packet.

  • CVE-2022-28705HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.01

    On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, on platforms with an ePVA and the pva.fwdaccel BigDB variable enabled, undisclosed requests to a virtual server with a…

  • CVE-2021-39762HigMar 30, 2022
    risk 0.49cvss 7.5epss 0.01

    In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID:…