CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,209 vulnerabilities with CWE-190
CVE-2017-14630 CRITICAL
sam2p 0.49.3 - Integer Overflow in pcxLoadImage24 Function
CVSS 9.8
CVE-2017-14629 HIGH
sam2p 0.49.3 - Denial of Service via Integer Signedness Error in in_xpm_reader
CVSS 7.5
CVE-2017-9607 HIGH
ARM Trusted Firmware <1.4 - Memory Corruption
CVSS 7.0
CVE-2017-14333 HIGH
GNU Binutils - Denial of Service via Crafted Binary File in readelf
CVSS 7.8
CVE-2017-14167 HIGH
QEMU < 2.10.2 - Integer Overflow in load_multiboot Function
CVSS 8.8
CVE-2017-14173 MEDIUM
ImageMagick 7.0.6-10 - Buffer Overflow
CVSS 6.5
CVE-2017-2870 HIGH
Gdk-Pixbuf 2.36.6 - Integer Overflow in TIFF Image Parser
CVSS 7.8
CVE-2017-14062 CRITICAL
Libidn2 < 2.0.4 - Integer Overflow in decode_digit Function
CVSS 9.8
CVE-2017-14061 CRITICAL
Libidn2 < 2.0.3 - Integer Overflow in _isBidi Function
CVSS 9.8
CVE-2017-14051 MEDIUM
Linux Kernel < 4.12.10 - Denial of Service via qla2x00_sysfs_write_optrom_ctl Integer Overflow
CVSS 4.4
CVE-2017-12797 MEDIUM
mpg123 < 1.25.4 - Denial of Service via ID3 Parser Integer Overflow
CVSS 5.5
CVE-2017-5208 HIGH
wrestool <0.31.1 - Memory Corruption
CVSS 8.8
CVE-2017-8267 HIGH
Qualcomm Android CAF - Integer Overflow via IOCTL Handler Race Condition
CVSS 7.0
CVE-2017-8255 HIGH
Qualcomm Android Boot - Integer Overflow
CVSS 7.8
CVE-2017-12864 HIGH
OpenCV < 3.3.0 - Integer Overflow in ReadNumber
CVSS 8.8
CVE-2017-12863 HIGH
OpenCV < 3.3.0 - Integer Overflow in PxMDecoder::readData
CVSS 8.8
CVE-2017-0729 HIGH
Android <7.1.2 - Privilege Escalation
CVSS 7.8
CVE-2017-12425 HIGH
Varnish 4.0.1-4.0.4 4.1.0-4.1.7 5.0.0 5.1.0-5.1.2 - Denial of Service via Integer Overflow
CVSS 7.5
CVE-2017-9835 HIGH
Ghostscript 9.21 - Denial of Service via Crafted PostScript Document
CVSS 7.8
CVE-2017-7542 MEDIUM
Linux kernel <= 4.12.3 - Denial of Service via Integer Overflow in ip6_find_1stfragopt
CVSS 5.5
CVE-2017-9765 HIGH
Genivia gSOAP 2.7.x-2.8.x < 2.8.48 - Remote Code Execution via Large XML Document
CVSS 8.1
CVE-2017-7529 HIGH
nginx 0.5.6-1.13.2 - Integer Overflow in Range Filter Module
CVSS 7.5
CVE-2017-2820 HIGH
Poppler 0.53.0 - Integer Overflow via JPEG 2000 Image Parsing
CVSS 8.8
CVE-2017-0702 HIGH
Android 7.1.1-7.1.2 - Remote Code Execution via Integer Overflow
CVSS 7.8
CVE-2017-0691 MEDIUM
Android 7.0-7.1.2 - Denial of Service in Media Framework
CVSS 5.5
Details
Vulnerabilities 3,209
Exploit Likelihood Medium