CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,210 vulnerabilities with CWE-190
CVE-2015-9190 CRITICAL
Qualcomm MDM9206 and Snapdragon Firmware - Integer Overflow in boot_clobber_check_local_address_range()
CVSS 9.8
CVE-2015-9183 CRITICAL
Qualcomm SD 410/12, SD 617, SD 650/52, SD 800, SD 808, SD 810 Firmware - Buffer Overflow via Set Certificates Command
CVSS 9.8
CVE-2015-9160 CRITICAL
Qualcomm Snapdragon Firmware - Integer Overflow in TZBSP_GFX_DCVS_UPDATE_ID
CVSS 9.8
CVE-2015-9150 CRITICAL
Qualcomm MDM9625, MDM9635M, SD 400, and SD 800 Firmware - Buffer Overflow via Diag Event Length Calculation
CVSS 9.8
CVE-2015-9148 CRITICAL
Qualcomm Snapdragon Automobile and Mobile Firmware - Buffer Overflow via Diag User-PD Command Registration
CVSS 9.8
CVE-2015-9133 CRITICAL
Qualcomm Snapdragon Mobile Integer Overflow via Widevine App TZ_WV_CMD_DECRYPT_VIDEO
CVSS 9.8
CVE-2015-1537 HIGH
Android < 4.4.4 - Remote Code Execution via Integer Overflow in IHDCP.cpp
CVSS 7.8
CVE-2015-1526 MEDIUM
Android < 4.4.4 - Denial of Service in media_server
CVSS 5.5
CVE-2015-1527 HIGH
Android - Integer Overflow in IAudioPolicyService
CVSS 7.8
CVE-2015-9062 CRITICAL
Qualcomm Android CAF - Integer Overflow to Buffer Overflow in ELF File Loading
CVSS 9.8
CVE-2015-2310 CRITICAL
capnproto < 0.4.1.1 - Integer Overflow in Pointer Validation
CVSS 9.1
CVE-2015-9005 HIGH
Android TrustZone - Integer Overflow to Buffer Overflow
CVSS 7.8
CVE-2015-1529 HIGH
Android - Denial of Service via Integer Overflow in ISoundTriggerHwService
CVSS 7.5
CVE-2015-8998 HIGH
Android TrustZone - Integer Overflow
CVSS 7.8
CVE-2015-8995 HIGH
Android TrustZone - Integer Overflow
CVSS 7.8
CVE-2015-8983 HIGH
glibc < 2.21 - Integer Overflow to Heap-Based Buffer Overflow in _IO_wstr_overflow
CVSS 8.1
CVE-2015-4645 MEDIUM
Squashfs < 4.3 - Denial of Service via Integer Overflow in Fragment Table Parsing
CVSS 5.5
CVE-2015-8982 HIGH
glibc < 2.20 - Integer Overflow in strxfrm Function
CVSS 8.1
CVE-2015-8895 HIGH
ImageMagick 6.9.1-3 and later - Denial of Service via Integer Overflow in Icon Coder
CVSS 7.5
CVE-2015-7599 HIGH
Wind River VxWorks <6.9.4.1 - DoS/Code Injection
CVSS 8.1
CVE-2015-7848 HIGH
NTP-dev.4.3.70 - Memory Corruption
CVSS 7.5
CVE-2015-8870 HIGH
libtiff < 4.0.3 - Integer Overflow via BMP RLE4/RLE8 Data
CVSS 7.4
CVE-2015-8933 MEDIUM
libarchive < 3.2.0 - Denial of Service via Integer Overflow in Tar Archive Reader
CVSS 5.5
CVE-2015-8931 HIGH
libarchive < 3.2.0 - Integer Overflow in MTREE Time Functions
CVSS 7.8
CVE-2015-8080 HIGH
Redis 2.8.0-2.8.23 - Integer Overflow in Lua getnum Function
CVSS 7.5
Details
Vulnerabilities 3,210
Exploit Likelihood Medium