VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,594)

page 78 of 180
  • CVE-2022-20685HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer overflow while processing Modbus traffic. An…

  • CVE-2024-42643HigOct 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Integer Overflow in fast_ping.c in SmartDNS Release46 allows remote attackers to cause a Denial of Service via misaligned memory access.

  • CVE-2024-47739HigOct 21, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: padata: use integer wrap around to prevent deadlock on seq_nr overflow When submitting more than 2^32 padata objects to padata_do_serial, the current sorting implementation incorrectly sorts padata objects…

  • CVE-2024-43566HigOct 17, 2024
    risk 0.49cvss 7.5epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2023-45854HigSep 16, 2024
    risk 0.49cvss 7.5epss 0.00

    A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shopping cart via the qtd parameter in the add-to-cart function.

  • CVE-2024-45287HigSep 5, 2024
    risk 0.49cvss 7.5epss 0.01

    A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required for the parsed data.

  • CVE-2024-45490HigAug 30, 2024
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

  • CVE-2024-33024HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length.

  • CVE-2024-36968HigJun 8, 2024
    risk 0.49cvss 7.6epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init() l2cap_le_flowctl_init() can cause both div-by-zero and an integer overflow since hdev->le_mtu may not fall in the valid range. Move MTU from…

  • CVE-2023-49441HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.01

    dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.

  • CVE-2023-41185HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Unified Automation UaGateway Certificate Parsing Integer Overflow Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is not required to…

  • CVE-2024-23531HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.02

    An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory.

  • CVE-2024-31031HigApr 17, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.

  • CVE-2024-21454HigApr 1, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while decoding the ToBeSignedMessage in Automotive Telematics.

  • CVE-2021-47109HigMar 15, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: neighbour: allow NUD_NOARP entries to be forced GCed IFF_POINTOPOINT interfaces use NUD_NOARP entries for IPv6. It's possible to fill up the neighbour table with enough entries that it will overflow for valid…

  • CVE-2023-24609HigDec 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in the TLS 1.3 server. An attacked device calculates an SHA-2 hash over at least 65 KB (in RAM). With a large number of crafted TLS…

  • CVE-2023-43826HigDec 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Apache Guacamole 1.5.3 and older do not consistently ensure that values received from a VNC server will not result in integer overflow. If a user connects to a malicious or compromised VNC server, specially-crafted data could result in memory corruption, possibly allowing…

  • CVE-2023-28588HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Bluetooth Host while rfc slot allocation.

  • CVE-2023-4398HigNov 28, 2023
    risk 0.49cvss 7.5epss 0.01

    An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37,…

  • CVE-2023-36395HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Deployment Services Denial of Service Vulnerability