CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,209 vulnerabilities with CWE-190
CVE-2017-9690 HIGH
Android for MSM - Integer Overflow to Buffer Overflow in qbt1000 IOCTL Handler
CVSS 7.8
CVE-2017-11085 HIGH
Android for MSM - Buffer Overflow in msm_audio_effects_virtualizer_handler
CVSS 7.8
CVE-2017-13136 HIGH
libbpg 0.9.7 - Integer Overflow via Image Allocation
CVSS 8.8
CVE-2017-16832 HIGH
GNU Binutils - Denial of Service via Crafted PE File in BFD Library
CVSS 7.8
CVE-2017-16831 HIGH
GNU Binutils - Integer Overflow in BFD Library via Crafted PE File
CVSS 7.8
CVE-2017-16830 HIGH
GNU Binutils 2.29.1 - Integer Overflow in print_gnu_property_note
CVSS 7.8
CVE-2017-16828 HIGH
GNU Binutils - Integer Overflow and Heap-Based Buffer Over-Read via Crafted ELF File
CVSS 7.8
CVE-2017-16797 HIGH
SWFTools 0.9.2 - Integer Overflow via PNG File Processing
CVSS 7.8
CVE-2017-16663 MEDIUM
sam2p 0.49.4 - Integer Overflow and Heap-Based Buffer Overflow in ReadImage Function
CVSS 5.5
CVE-2017-2921 CRITICAL
Cesanta Mongoose 6.8 - Denial of Service and Potential Remote Code Execution via Websocket Packet Integer Overflow
CVSS 9.8
CVE-2017-2892 CRITICAL
Cesanta Mongoose 6.8 - Arbitrary Memory Read and Write via MQTT Packet Parsing
CVSS 9.8
CVE-2017-1000121 CRITICAL
WebKitGTK+ < 2.16.3 - Integer Overflow and Buffer Overflow via IPC Message Size Metadata
CVSS 9.8
CVE-2017-10954 HIGH
Bitdefender Internet Security 2018 < 7.72918 - Remote Code Execution via Integer Overflow in pdf.xmd
CVSS 8.8
CVE-2017-5063 HIGH
Google Chrome <58.0.3029 - Memory Corruption
CVSS 8.8
CVE-2017-15873 MEDIUM
BusyBox - Integer Overflow in get_next_block Function
CVSS 5.5
CVE-2017-15587 HIGH
Artifex MuPDF - Integer Overflow in pdf_read_new_xref_section
CVSS 7.8
CVE-2017-2888 HIGH
Simple DirectMedia Layer 2.0.5 - Integer Overflow in RGB Surface Creation
CVSS 8.8
CVE-2017-9683 HIGH
Android - Integer Overflow in Meta Image Flashing
CVSS 7.8
CVE-2017-14861 MEDIUM
exiv2 - Denial of Service via Stack Consumption in stringFormat Function
CVSS 5.5
CVE-2017-14745 HIGH
GNU Binutils - Denial of Service via Crafted ELF File in BFD Library
CVSS 7.8
CVE-2017-14636 CRITICAL
sam2p 0.49.3 - Integer Overflow and Memory Corruption in Image::Indexed::sortPal
CVSS 9.8
CVE-2017-9282 CRITICAL
Micro Focus VisiBroker 8.5 - Memory Corruption
CVSS 9.8
CVE-2017-9281 HIGH
Micro Focus VisiBroker 8.5 - Memory Corruption
CVSS 7.5
CVE-2017-8278 HIGH
Android < 8.0 - Buffer Overflow in Audio Driver
CVSS 7.8
CVE-2017-8250 HIGH
Android < 8.0 - Integer Overflow to Buffer Overflow via Unchecked User Variables
CVSS 7.8
Details
Vulnerabilities 3,209
Exploit Likelihood Medium