CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,209 vulnerabilities with CWE-190
CVE-2017-12465 CRITICAL
ccn-lite < 2.0.0 - Integer Overflow in iottlv_parse_sequence and localrpc_parse
CVSS 9.8
CVE-2017-18043 MEDIUM
QEMU 1.5.0-2.10.0 - Denial of Service via Integer Overflow in ROUND_UP Macro
CVSS 5.5
CVE-2017-12179 CRITICAL
xorg-x11-server <1.19.5 - Memory Corruption
CVSS 9.8
CVE-2017-12177 CRITICAL
xorg-x11-server <1.19.5 - Memory Corruption
CVSS 9.8
CVE-2017-13182 HIGH
Android 8.0-8.1 - Integer Overflow to Out-of-Bounds Write in ACodec sendFormatChange
CVSS 7.8
CVE-2017-0869 HIGH
Android NVIDIA Driver - Integer Overflow to Use-After-Free and Privilege Escalation
CVSS 7.8
CVE-2017-4950 HIGH
VMware Workstation and Fusion - Buffer Overflow
CVSS 7.0
CVE-2017-1000470 HIGH
EmbedThis GoAhead Webserver <4.0.0 - DoS
CVSS 7.5
CVE-2017-1000422 HIGH
Gnome gdk-pixbuf <2.36.8 - Memory Corruption
CVSS 8.8
CVE-2017-1000450 HIGH
OpenCV < 3.3.0 - Integer Overflow in FillUniColor and FillUniGray
CVSS 8.8
CVE-2017-17863 HIGH
Linux Kernel 4.9.0-4.9.71 - Denial of Service via BPF Stack Pointer Calculation
CVSS 7.8
CVE-2017-17854 HIGH
Linux Kernel < 4.14.9 - Integer Overflow in BPF Verifier
CVSS 7.8
CVE-2017-17409 HIGH
Bitdefender Internet Security 2018 - RCE
CVSS 8.8
CVE-2017-17408 HIGH
Bitdefender Internet Security 2018 - RCE
CVSS 8.8
CVE-2017-11043 HIGH
Android for MSM, Firefox OS for MSM, QRD Android - Heap Buffer Overflow via WiFi Driver Integer Overflow
CVSS 7.8
CVE-2017-17426 HIGH
glibc 2.26 - Heap Overflow via Integer Overflow in malloc tcache
CVSS 8.1
CVE-2017-17122 HIGH
GNU Binutils - Denial of Service via Crafted PE File
CVSS 7.8
CVE-2017-16612 HIGH
libXcursor <1.1.15 - Memory Corruption
CVSS 7.5
CVE-2017-8816 CRITICAL
curl and libcurl < 7.57.0 - Denial of Service via NTLM Authentication Integer Overflow
CVSS 9.8
CVE-2017-8205 HIGH
Honor 9 Firmware < Stanford-AL10C00B175 - Integer Overflow in Bastet Driver
CVSS 7.8
CVE-2017-2717 MEDIUM
Huawei Honor 8 Pro Firmware Integer Overflow via Response Message Length Field
CVSS 6.5
CVE-2017-12110 HIGH
libxls <1.4 - Remote Code Execution
CVSS 8.8
CVE-2017-1000229 HIGH
optipng 0.7.6 - Integer Overflow in minitiff_read_info()
CVSS 7.8
CVE-2017-1000158 CRITICAL
CPython < 2.7.15 - Integer Overflow to Heap-Based Buffer Overflow in PyString_DecodeEscape
CVSS 9.8
CVE-2017-0841 HIGH
Android 5.0.2 5.1.1 6.0 6.0.1 7.0 7.1.1 7.1.2 8.0 - Remote Code Execution via Integer Overflow in libutils
CVSS 7.8
Details
Vulnerabilities 3,209
Exploit Likelihood Medium