CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,209 vulnerabilities with CWE-190
CVE-2016-7511 MEDIUM
libdwarf 20160613 - Denial of Service via Integer Overflow in dwarf_die_deliv.c
CVSS 5.5
CVE-2016-6872 CRITICAL
Facebook HHVM < 3.14.5 - Integer Overflow in StringUtil::implode
CVSS 9.8
CVE-2016-6871 CRITICAL
Facebook HHVM < 3.14.5 - Integer Overflow in bcmath
CVSS 9.8
CVE-2016-6252 HIGH
Shadow 4.2.1 - Privilege Escalation
CVSS 7.8
CVE-2016-1889 HIGH
FreeBSD <11.0 - Privilege Escalation
CVSS 7.8
CVE-2016-8859 CRITICAL
TRE library/musl libc - Memory Corruption
CVSS 9.8
CVE-2016-2147 HIGH
BusyBox < 1.25.0 - Denial of Service via DHCP Client Integer Overflow
CVSS 7.5
CVE-2016-9108 HIGH
MuJS <b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e - DoS
CVSS 7.5
CVE-2016-9085 LOW
libwebp < 0.5.2 - Integer Overflow
CVSS 3.3
CVE-2016-9082 MEDIUM
cairo 1.14.6 - Denial of Service via Integer Overflow in write_png Function
CVSS 5.5
CVE-2016-4352 MEDIUM
libavformat < 57.34.103 - Denial of Service via GIF Demuxer Integer Overflow
CVSS 5.5
CVE-2016-10164 CRITICAL
libXpm < 3.5.12 - Heap-Based Buffer Overflow via Crafted XPM File
CVSS 9.8
CVE-2016-9132 CRITICAL
Botan 1.8.0-1.11.33 - Memory Corruption
CVSS 9.8
CVE-2016-2399 HIGH
libquicktime < 1.2.4 - Integer Overflow in quicktime_read_pascal Function
CVSS 7.8
CVE-2016-7938 CRITICAL
tcpdump < 4.8.1 - Integer Overflow in ZeroMQ Parser
CVSS 9.8
CVE-2016-10159 HIGH
PHP < 5.6.30 and 7.0.x < 7.0.15 - Denial of Service via Truncated PHAR Archive Manifest
CVSS 7.5
CVE-2016-9445 HIGH
GStreamer - Integer Overflow in VMNC Decoder
CVSS 7.5
CVE-2016-6164 CRITICAL
FFmpeg <2.8.8, <3.0.3, <3.1.1 - Buffer Overflow
CVSS 9.8
CVE-2016-5223 MEDIUM
Google Chrome < 55.0.2883.75 - Integer Overflow in PDFium via Crafted PDF File
CVSS 6.5
CVE-2016-5221 MEDIUM
Google Chrome < 55.0.2883.75 - Type Confusion in libGLESv2
CVSS 6.3
CVE-2016-6823 HIGH
ImageMagick < 6.9.10-50 - Denial of Service via BMP Height and Width Integer Overflow
CVSS 7.5
CVE-2016-10141 CRITICAL
MuJS <fa3d30fd18c348bb4b1f3858fb860f4fcd4b2045 - Buffer Overflow
CVSS 9.8
CVE-2016-8438 CRITICAL
Android Kernel <3.18 - Privilege Escalation
CVSS 9.8
CVE-2016-8706 HIGH
memcached < 1.4.31 - Remote Code Execution via Integer Overflow in process_bin_sasl_auth
CVSS 8.1
CVE-2016-8705 CRITICAL
memcached < 1.4.31 - Remote Code Execution via Integer Overflow in process_bin_update
CVSS 9.8
Details
Vulnerabilities 3,209
Exploit Likelihood Medium