CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,209 vulnerabilities with CWE-190
CVE-2017-5049 HIGH
Google Chrome < 57.0.2987.98 - Integer Overflow in FFmpeg ChunkDemuxer
CVSS 8.8
CVE-2017-5048 HIGH
Google Chrome < 57.0.2987.98 - Integer Overflow in FFmpeg via Crafted Video File
CVSS 8.8
CVE-2017-5047 HIGH
Google Chrome < 57.0.2987.98 - Integer Overflow in FFmpeg via Crafted Video File
CVSS 8.8
CVE-2017-5037 HIGH
Google Chrome < 57.0.2987.98 - Integer Overflow in FFmpeg via Crafted Video File
CVSS 7.8
CVE-2017-3599 HIGH
MySQL Server <5.6.35, <5.7.17 - DoS
CVSS 7.5
CVE-2017-7982 MEDIUM
libplist < 1.12 - Denial of Service via Integer Overflow in plist_from_bin
CVSS 5.5
CVE-2017-7976 HIGH
Artifex jbig2dec 0.13 - Integer Overflow in jbig2_image_compose Function
CVSS 7.1
CVE-2017-7975 HIGH
Artifex jbig2dec 0.13 - Integer Overflow in jbig2_build_huffman_table
CVSS 7.8
CVE-2017-7948 HIGH
Artifex Ghostscript - Integer Overflow in mark_curve Function
CVSS 7.8
CVE-2017-7885 HIGH
Artifex jbig2dec 0.13 - Heap-Based Buffer Over-Read via Crafted .jb2 File
CVSS 7.1
CVE-2017-3011 HIGH
Adobe Acrobat < 11.0.19 - Integer Overflow
CVSS 7.8
CVE-2017-7603 HIGH
libaacplus 2.0.2 - Integer Overflow via Crafted Audio File
CVSS 7.8
CVE-2017-7602 HIGH
LibTIFF 4.0.7 - Integer Overflow via Crafted Image
CVSS 7.8
CVE-2017-0576 HIGH
Linux Kernel - Integer Overflow in Qualcomm Crypto Engine Driver
CVSS 7.0
CVE-2017-0553 HIGH
Android 5.0.2 5.1.1 6.0 6.0.1 7.0 7.1.1 - Elevation of Privilege via libnl Integer Overflow
CVSS 7.0
CVE-2017-2440 HIGH
iPhone OS < 10.3, macOS < 10.12.4, tvOS < 10.2, watchOS < 3.2 - RCE or DoS via Integer Overflow
CVSS 7.8
CVE-2017-7395 MEDIUM
TigerVNC 1.7.1 - Authenticated Denial of Service via Integer Overflow in SMsgReader
CVSS 6.5
CVE-2017-7294 HIGH
Linux kernel <4.10.6 - Privilege Escalation
CVSS 7.8
CVE-2017-5931 HIGH
QEMU < 2.8.1.1 - Integer Overflow in virtio-crypto Request Handling
CVSS 8.8
CVE-2017-6839 MEDIUM
audiofile 0.3.6 - Denial of Service via Integer Overflow in MSADPCM.cpp
CVSS 5.5
CVE-2017-6838 MEDIUM
audiofile 0.3.6 - Denial of Service via Integer Overflow in sfconvert
CVSS 5.5
CVE-2017-6962 HIGH
apng2gif 1.7 - Heap-Based Buffer Overflow via Integer Overflow in read_chunk
CVSS 7.5
CVE-2017-6960 HIGH
apng2gif 1.7 - Heap-Based Buffer Over-Read via Integer Overflow in load_apng
CVSS 7.5
CVE-2017-0104 HIGH
iSNS Server in Windows Server 2008 SP2/R2, 2012 Gold/R2, 2016 - Remote Code Execution via Integer Overflow
CVSS 8.1
CVE-2017-6952 HIGH
capstone < 3.0.4 - Integer Overflow in cs_winkernel_malloc
CVSS 8.8
Details
Vulnerabilities 3,209
Exploit Likelihood Medium