VYPR

CWE-682

Incorrect Calculation

PillarDraftLikelihood: High

Description

The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.

When product performs a security-critical calculation incorrectly, it might lead to incorrect resource allocations, incorrect privilege assignments, or failed comparisons among other things. Many of the direct results of an incorrect calculation can lead to even larger problems such as failed protection mechanisms or even arbitrary code execution.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-128 · CAPEC-129

CVEs mapped to this weakness (145)

page 3 of 8
  • CVE-2019-16346HigSep 16, 2019
    risk 0.50cvss 8.8epss 0.02

    ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled.

  • CVE-2025-55552HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.

  • CVE-2022-35258HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.03

    An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust…

  • CVE-2022-22138HigJun 17, 2022
    risk 0.49cvss 7.5epss 0.01

    All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.

  • CVE-2021-44504HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a size variable, stored as an signed int, to equal an extremely large value, which is interpreted as a negative value during a check. This value is…

  • CVE-2021-44491HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a segmentation fault and crash the…

  • CVE-2021-44490HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a segmentation fault and crash the…

  • CVE-2022-23011HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On certain hardware BIG-IP platforms, in version 15.1.x before 15.1.4 and 14.1.x before 14.1.3, virtual servers may stop responding while processing TCP traffic due to an issue in the SYN Cookie Protection feature. Note: Software versions which have reached End of Technical…

  • CVE-2020-28393HigMay 12, 2021
    risk 0.49cvss 7.5epss 0.02

    An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device on the SCALANCE XM-400, XR-500 (All versions prior to v6.4).

  • CVE-2021-3004HigJan 3, 2021
    risk 0.49cvss 7.5epss 0.01

    The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should.

  • CVE-2019-2232HigDec 6, 2019
    risk 0.49cvss 7.5epss 0.01

    In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service when processing Unicode with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2019-17514HigOct 12, 2019
    risk 0.49cvss 7.5epss 0.05

    library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether sorting occurs, as demonstrated by irreproducible cancer-research results. NOTE: the effects of this documentation cross application domains, and thus it is…

  • CVE-2018-20999HigAug 26, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the orion crate before 0.11.2 for Rust. reset() calls cause incorrect results.

  • CVE-2018-18225HigOct 12, 2018
    risk 0.49cvss 7.5epss 0.03

    In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.

  • CVE-2018-15391HigOct 5, 2018
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in certain IPv4 fragment-processing functions of Cisco Remote PHY Software could allow an unauthenticated, remote attacker to impact traffic passing through a device, potentially causing a denial of service (DoS) condition. The vulnerability is due to the…

  • CVE-2018-14439HigJul 20, 2018
    risk 0.49cvss 7.5epss 0.01

    espritblock eos4j, an unofficial SDK for EOS, through 2018-07-12 mishandles floating-point numbers with more than four digits after the decimal point, which might allow attackers to trigger currency transfers of unintended amounts.

  • CVE-2017-0819HigOct 4, 2017
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63045918.

  • CVE-2019-1918HigAug 7, 2019
    risk 0.48cvss 7.4epss 0.01

    A vulnerability in the implementation of Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS-IS area to cause a denial of service (DoS)…

  • CVE-2024-41011HigJul 18, 2024
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: don't allow mapping the MMIO HDP page with large pages We don't get the right offset in that case. The GPU has an unused 4K area of the register BAR space into which you can remap registers. We…

  • CVE-2026-47247HigJul 21, 2026
    risk 0.42cvss 7.5epss 0.00

    libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor…