VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,594)

page 80 of 180
  • CVE-2022-2831HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption.

  • CVE-2022-36125HigAug 9, 2022
    risk 0.49cvss 7.5epss 0.02

    It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.

  • CVE-2022-31600HigJul 4, 2022
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmmCore, where a user with high privileges can chain another vulnerability to this vulnerability, causing an integer overflow, possibly leading to code execution, escalation of privileges, denial of service, compromised…

  • CVE-2022-28937HigMay 15, 2022
    risk 0.49cvss 7.5epss 0.01

    FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an invalid header, will cause normal nodes to stop producing new blocks and processing new clients' requests.

  • CVE-2022-28936HigMay 15, 2022
    risk 0.49cvss 7.5epss 0.01

    FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow and cause a Denial of Service (DoS) via an unusually large viewchange message packet.

  • CVE-2022-28705HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.01

    On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, on platforms with an ePVA and the pva.fwdaccel BigDB variable enabled, undisclosed requests to a virtual server with a…

  • CVE-2021-39762HigMar 30, 2022
    risk 0.49cvss 7.5epss 0.01

    In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID:…

  • CVE-2022-25062HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.04

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

  • CVE-2021-22319HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause integer overflows.

  • CVE-2022-23772HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.03

    Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.

  • CVE-2022-21801HigJan 28, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the netserver recv_command functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to a reboot. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2021-38787HigJan 19, 2022
    risk 0.49cvss 7.5epss 0.02

    There is an integer overflow in the ION driver "/dev/ion" of Allwinner R818 SoC Android Q SDK V1.0 that could use the ioctl cmd "COMPAT_ION_IOC_SUNXI_FLUSH_RANGE" to cause a system crash (denial of service).

  • CVE-2020-7881HigNov 26, 2021
    risk 0.49cvss 7.5epss 0.01

    The vulnerability function is enabled when the streamer service related to the AfreecaTV communicated through web socket using 21201 port. A stack-based buffer overflow leading to remote code execution was discovered in strcpy() operate by "FanTicket" field. It is because of…

  • CVE-2021-43618HigNov 15, 2021
    risk 0.49cvss 7.5epss 0.04

    GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.

  • CVE-2021-0630HigOct 25, 2021
    risk 0.49cvss 7.5epss 0.01

    In wifi driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05551397; Issue ID: ALPS05551397.

  • CVE-2021-41991HigOct 18, 2021
    risk 0.49cvss 7.5epss 0.05

    The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by…

  • CVE-2021-41990HigOct 18, 2021
    risk 0.49cvss 7.5epss 0.07

    The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.

  • CVE-2021-27665HigOct 11, 2021
    risk 0.49cvss 7.5epss 0.02

    An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a specially crafted script and cause denial-of-service condition.

  • CVE-2021-41099HigOct 4, 2021
    risk 0.49cvss 7.5epss 0.04

    Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the underlying string library can be used to corrupt the heap and potentially result with denial of service or remote code execution. The vulnerability involves changing the default…

  • CVE-2021-32762HigOct 4, 2021
    risk 0.49cvss 7.5epss 0.03

    Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network replies. This is a result of a vulnerability in the…