CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,173 vulnerabilities with CWE-190
CVE-2026-24403 HIGH
iccDEV <2.3.1.1 - Memory Corruption
CVSS 7.1
CVE-2026-0988 LOW
RHEL 6-10 & Hardened Images - DoS via Integer Overflow in g_buffered_input_stream_peek
CVSS 3.7
CVE-2026-23876 HIGH
ImageMagick <7.1.2-13 & <6.9.13-38 - Buffer Overflow
CVSS 8.1
CVE-2026-23833 HIGH
ESPHome 2025.9.0-2025.12.6 - Unauthenticated Denial of Service via API Protobuf Decoder Integer Overflow
CVSS 7.5
CVE-2026-0861 HIGH
GNU C Library 2.30-2.42 - Integer Overflow via Large Alignment in memalign Suite
CVSS 8.4
CVE-2026-0880 HIGH
Firefox < 115.32.0 and 140.7-147.0 - Sandbox Escape via Graphics Integer Overflow
CVSS 8.8
CVE-2026-22801 MEDIUM
libpng 1.6.26-1.6.53 - Heap Buffer Over-read via Negative Row Stride
CVSS 6.8
CVE-2026-21689 MEDIUM
iccDEV < 2.3.1.2 - Type Confusion in CIccProfileXml::ParseBasic()
CVSS 6.5
CVE-2026-21688 HIGH
iccDEV < 2.3.1.2 - Type Confusion in SIccCalcOp::ArgsPushed()
CVSS 8.8
CVE-2026-21486 HIGH
iccdev < 2.3.1.2 - Heap-based Buffer Overflow in CIccSparseMatrix
CVSS 7.8
CVE-2026-21485 HIGH
iccdev < 2.3.1.2 - Out-of-bounds Read
CVSS 8.8
CVE-2026-21673 HIGH
iccDEV < 2.3.1.1 - Integer Overflow in CIccXmlArrayType::ParseTextCountNum()
CVSS 7.8
CVE-2025-55647 MEDIUM
GPAC MP4Box 2.4 - Denial of Service via Crafted MP4 File
CVSS 5.5
CVE-2025-14098 HIGH
Avira antivirus engine heap buffer OOB write when scanning a malformed MS-DOS executable file
CVSS 7.8
CVE-2025-66280 HIGH
QNAP Systems - QTS, QuTS Hero
CVSS 7.2
CVE-2025-48595 HIGH KEV
Google Android - Integer Overflow or Wraparound
CVSS 8.4
CVE-2025-47392 HIGH
Integer Overflow or Wraparound in GPS
CVSS 8.8
CVE-2025-43238 MEDIUM
macOS < 13.7.7, < 14.7.7, < 15.6 - Denial of Service via Integer Overflow
CVSS 6.2
CVE-2025-46597 HIGH
Bitcoin Core 0.13.0-29.x - Memory Corruption
CVSS 7.5
CVE-2025-15584 MEDIUM
Endpoint DLP Driver Filter Communication Port Integer Overflow
CVE-2025-66168 MEDIUM
Apache ActiveMQ - Memory Corruption
CVSS 5.4
CVE-2025-48515 MEDIUM
AMD Secure Processor < - Memory Corruption
CVE-2025-64098 MEDIUM
Fast DDS < 2.6.11 - Denial of Service via Tampered DATA Submessage in SPDP Packet
CVSS 5.9
CVE-2025-62600 HIGH
eProsima Fast DDS <2.6.11, 2.7.0-2.14.5, 3.0.0-3.2.3, 3.3.0, 3.4.0-3.4.1 - Remote DoS via SPDP Packet Tampering
CVSS 8.6
CVE-2025-62599 HIGH
eProsima Fast DDS < 2.6.11, 2.7.0-2.14.5, 3.0.0-3.2.3, 3.3.0, 3.4.0 - Remote DoS via SPDP Packet Tampering
CVSS 8.6
Details
Vulnerabilities 3,173
Exploit Likelihood Medium