The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
3,210 vulnerabilities with CWE-190
CVE-2015-8651
HIGH
KEV
Adobe Flash Player < 18.0.0.324, 19.x-20.x < 20.0.0.267, AIR < 20.0.0.233 - Remote Code Execution
CVSS 8.8
CVE-2015-8394
CRITICAL
PCRE < 8.38 - Integer Overflow via Crafted Regular Expression
CVSS 9.8
CVE-2015-8387
HIGH
PCRE < 8.38 - Integer Overflow via Subroutine Call in Regular Expression
CVSS 7.3
CVE-2015-5707
Linux Kernel 2.6.0-4.0 - Integer Overflow in sg_start_req via Large iov_count Value
CVE-2015-2519
Windows Journal - Remote Code Execution via Crafted .jnt File
CVE-2015-5621
HIGH
net-snmp < 5.7.2 - Denial of Service and Possible Remote Code Execution via Crafted SNMP PDU
CVSS 7.5
CVE-2015-1283
Google Chrome < 43.0.2357.134 - Integer Overflow via Crafted XML Data
CVE-2015-5109
Adobe Acrobat/Reader RCE via Integer Overflow (10.x<10.1.15, 11.x<11.0.12, DC<2015.006.30060/2015.008.20082)
CVE-2015-5108
Adobe Acrobat and Reader Remote Code Execution via Integer Overflow
CVE-2015-5097
Adobe Acrobat/Reader RCE via Integer Overflow (10.x<10.1.15, 11.x<11.0.12, DC<2015.006.30060/2015.008.20082)
CVE-2015-3416
SQLite <3.8.9 - DoS
CVE-2015-2305
rxspencer alpha3.8.g5 - Integer Overflow via Large Regular Expression
CVE-2015-1214
Skia <41.0.2272.76 - DoS
CVE-2015-0886
jBCrypt < 0.4 - Integer Overflow in Key-Stretching Implementation
CVE-2014-0147
MEDIUM
Qemu < 1.6.2 - Denial of Service via QCOW2 Snapshot Refcount Logic Error
CVSS 6.2
CVE-2014-4607
HIGH
Oberhumer liblzo2/lzo-2 <2.07 - RCE
CVSS 8.8
CVE-2014-4860
MEDIUM
EDK2 - Integer Overflow in Capsule Update PEI Boot Phase
CVSS 6.8
CVE-2014-4859
MEDIUM
EDK2 - Integer Overflow in Capsule Update Feature
CVSS 6.8
CVE-2014-4610
HIGH
FFmpeg < 0.10.14 - Remote Code Execution via Crafted Literal Run in LZO Decompression
CVSS 8.8
CVE-2014-4609
HIGH
libav < 0.8.13 - Remote Code Execution via Crafted Literal Run in LZO Decompression
CVSS 8.8
CVE-2014-9994
CRITICAL
Qualcomm Snapdragon Mobile SD 400 and SD 800 Firmware - Buffer Overflow via Integer Overflow
CVSS 9.8
CVE-2014-2885
HIGH
TrueCrypt 7.1a - Integer Overflow in EncryptedIoQueue.c and Ntdriver.c
CVSS 7.1
CVE-2014-5044
CRITICAL
libgfortran < 4.8 - Integer Overflow in Array Allocation
CVSS 9.8
CVE-2014-0143
HIGH
QEMU <2.0.0 - Denial of Service
CVSS 7.0
CVE-2014-9964
HIGH
Android - Integer Overflow in Debug Functionality
CVSS 7.8
Details
Vulnerabilities
3,210
Exploit Likelihood
Medium