CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,209 vulnerabilities with CWE-190
CVE-2017-5898 MEDIUM
Qemu < 2.8.1.1 - Denial of Service via Large APDU Unit in CCID Card Emulator
CVSS 5.5
CVE-2017-6440 MEDIUM
libplist 1.12 - Denial of Service via Crafted Plist File
CVSS 5.0
CVE-2017-6355 MEDIUM
virglrenderer < 0.5.0 - Denial of Service via Integer Overflow in vrend_create_shader
CVSS 5.5
CVE-2017-6312 MEDIUM
gdk-pixbuf < 2.36.12 - Denial of Service via Crafted ICO Image Entry Offset
CVSS 5.5
CVE-2017-0521 HIGH
Linux Kernel - Integer Overflow in Qualcomm Camera Driver
CVSS 7.0
CVE-2017-0307 HIGH
Linux Kernel < 3.18 - Local Privilege Escalation via NVIDIA GPU Driver Integer Overflow
CVSS 7.8
CVE-2017-5853 HIGH
PoDoFo 0.9.4 - Integer Overflow in PdfParser.cpp
CVSS 7.8
CVE-2017-5501 MEDIUM
JasPer 1.900.17 - Denial of Service via Integer Overflow in jpc_tsfb.c
CVSS 5.5
CVE-2017-5499 MEDIUM
JasPer 1.900.17 - Denial of Service via Integer Overflow in jpc_dec.c
CVSS 5.5
CVE-2017-5885 CRITICAL
Fedora < 0.6.0 - Integer Overflow
CVSS 9.8
CVE-2017-6350 CRITICAL
vim < 8.0.0377 - Integer Overflow via Undo File Deserialization
CVSS 9.8
CVE-2017-6349 CRITICAL
vim < 8.0.0376 - Integer Overflow in Undo File Processing
CVSS 9.8
CVE-2017-6308 HIGH
tnef < 1.4.13 - Integer Overflow and Heap Overflow via Memory Allocation Wrapper
CVSS 7.8
CVE-2017-6303 HIGH
ytnef < 1.9.1 - Integer Overflow or Wraparound
CVSS 7.8
CVE-2017-6302 HIGH
ytnef < 1.9.1 - Integer Overflow
CVSS 7.8
CVE-2017-0309 HIGH
NVIDIA GPU Display Driver - Integer Overflow in Kernel Mode Layer Handler
CVSS 8.8
CVE-2017-2987 HIGH
Adobe Flash Player <= 24.0.0.194 - Remote Code Execution via Integer Overflow
CVSS 8.8
CVE-2017-5953 CRITICAL
vim < 8.0.0055 - Integer Overflow and Buffer Overflow via Spell File Tree Length
CVSS 9.8
CVE-2017-0410 HIGH
Android 5.0.2 5.1.1 6.0 6.0.1 7.0 7.1.1 - Elevation of Privilege via Framework APIs
CVSS 7.8
CVE-2017-5576 HIGH
Linux Kernel < 4.9.7 - Integer Overflow in VideoCore DRM Driver via VC4_SUBMIT_CL ioctl
CVSS 7.8
CVE-2017-5628 HIGH
Artifex MuJS < 2017-01-24 - Integer Overflow in MakeDay Function
CVSS 7.8
CVE-2017-5627 HIGH
Artifex MuJS < 2017-01-24 - Integer Overflow via Negative Array Length in jsR_setproperty
CVSS 7.8
CVE-2017-5597 HIGH
Wireshark 2.0.0-2.0.9 and 2.2.0-2.2.3 - Denial of Service via DHCPv6 Dissector Integer Overflow
CVSS 7.5
CVE-2017-5596 HIGH
Wireshark 2.0.0-2.0.9 and 2.2.0-2.2.3 - Denial of Service via ASTERIX Dissector Integer Overflow
CVSS 7.5
CVE-2017-0383 HIGH
Android 7.0-7.1 - Elevation of Privilege via Framework APIs
CVSS 7.8
Details
Vulnerabilities 3,209
Exploit Likelihood Medium