CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,209 vulnerabilities with CWE-190
CVE-2017-10791 MEDIUM
GNU PSPP - Integer Overflow in hash_int Function
CVSS 6.5
CVE-2017-9832 MEDIUM
libmtp <1.1.12 - DoS/Remote Code Execution
CVSS 6.8
CVE-2017-9831 MEDIUM
libmtp <1.1.12 - DoS/Remote Code Execution
CVSS 6.8
CVE-2017-9776 HIGH
Poppler < 0.55.0 - Integer Overflow and Heap Buffer Overflow in JBIG2Stream.cc
CVSS 7.8
CVE-2017-2782 MEDIUM
MatrixSSL 3.8.7b - Integer Overflow in X509 Certificate Parser
CVSS 6.5
CVE-2017-2813 HIGH
IrfanView 4.44 - Integer Overflow in JPEG 2000 Parser
CVSS 8.8
CVE-2017-4913 HIGH
VMware Workstation <12.5.3 - Code Injection
CVSS 7.8
CVE-2017-8782 MEDIUM
libming 0.4.8 - Denial of Service via Integer Overflow in readString Function
CVSS 6.5
CVE-2017-9200 CRITICAL
AutoTrace <0.31.1 - Buffer Overflow
CVSS 9.8
CVE-2017-9199 CRITICAL
AutoTrace 0.31.1 - Integer Overflow in input-tga.c
CVSS 9.8
CVE-2017-9198 CRITICAL
AutoTrace <0.31.1 - Buffer Overflow
CVSS 9.8
CVE-2017-9197 CRITICAL
AutoTrace <0.31.1 - Buffer Overflow
CVSS 9.8
CVE-2017-9196 CRITICAL
AutoTrace <0.31.1 - Buffer Overflow
CVSS 9.8
CVE-2017-9187 CRITICAL
AutoTrace 0.31.1 - Integer Overflow in input-bmp.c
CVSS 9.8
CVE-2017-9186 CRITICAL
AutoTrace 0.31.1 - Integer Overflow in input-bmp.c
CVSS 9.8
CVE-2017-9185 CRITICAL
AutoTrace <0.31.1 - Buffer Overflow
CVSS 9.8
CVE-2017-9184 CRITICAL
AutoTrace 0.31.1 - Integer Overflow in input-bmp.c
CVSS 9.8
CVE-2017-9162 CRITICAL
AutoTrace 0.31.1 - Integer Overflow in autotrace.c
CVSS 9.8
CVE-2017-9161 CRITICAL
AutoTrace <0.31.1 - Buffer Overflow
CVSS 9.8
CVE-2017-6889 CRITICAL
LibRaw-demosaic-pack-GPL2 <0.18.2 - Buffer Overflow
CVSS 9.8
CVE-2017-0611 HIGH
Linux Kernel - Local Privilege Escalation via Qualcomm Sound Driver Integer Overflow
CVSS 7.0
CVE-2017-0603 MEDIUM
Android 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2 - Denial of Service via Crafted File in libstagefright
CVSS 4.7
CVE-2017-0597 HIGH
Android 4.4.4 5.0.2 5.1.1 6.0 6.0.1 7.0 7.1.1 7.1.2 - Elevation of Privilege via Audioserver Integer Overflow
CVSS 7.8
CVE-2017-5051 HIGH
Google Chrome < 57.0.2987.98 - Remote Code Execution via FFmpeg Integer Overflow
CVSS 8.8
CVE-2017-5050 HIGH
Google Chrome < 57.0.2987.98 - Integer Overflow in FFmpeg ChunkDemuxer
CVSS 8.8
Details
Vulnerabilities 3,209
Exploit Likelihood Medium