CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,210 vulnerabilities with CWE-190
CVE-2015-8651 HIGH KEV
Adobe Flash Player < 18.0.0.324, 19.x-20.x < 20.0.0.267, AIR < 20.0.0.233 - Remote Code Execution
CVSS 8.8
CVE-2015-8394 CRITICAL
PCRE < 8.38 - Integer Overflow via Crafted Regular Expression
CVSS 9.8
CVE-2015-8387 HIGH
PCRE < 8.38 - Integer Overflow via Subroutine Call in Regular Expression
CVSS 7.3
CVE-2015-5707
Linux Kernel 2.6.0-4.0 - Integer Overflow in sg_start_req via Large iov_count Value
CVE-2015-2519
Windows Journal - Remote Code Execution via Crafted .jnt File
CVE-2015-5621 HIGH
net-snmp < 5.7.2 - Denial of Service and Possible Remote Code Execution via Crafted SNMP PDU
CVSS 7.5
CVE-2015-1283
Google Chrome < 43.0.2357.134 - Integer Overflow via Crafted XML Data
CVE-2015-5109
Adobe Acrobat/Reader RCE via Integer Overflow (10.x<10.1.15, 11.x<11.0.12, DC<2015.006.30060/2015.008.20082)
CVE-2015-5108
Adobe Acrobat and Reader Remote Code Execution via Integer Overflow
CVE-2015-5097
Adobe Acrobat/Reader RCE via Integer Overflow (10.x<10.1.15, 11.x<11.0.12, DC<2015.006.30060/2015.008.20082)
CVE-2015-3416
SQLite <3.8.9 - DoS
CVE-2015-2305
rxspencer alpha3.8.g5 - Integer Overflow via Large Regular Expression
CVE-2015-1214
Skia <41.0.2272.76 - DoS
CVE-2015-0886
jBCrypt < 0.4 - Integer Overflow in Key-Stretching Implementation
CVE-2014-0147 MEDIUM
Qemu < 1.6.2 - Denial of Service via QCOW2 Snapshot Refcount Logic Error
CVSS 6.2
CVE-2014-4607 HIGH
Oberhumer liblzo2/lzo-2 <2.07 - RCE
CVSS 8.8
CVE-2014-4860 MEDIUM
EDK2 - Integer Overflow in Capsule Update PEI Boot Phase
CVSS 6.8
CVE-2014-4859 MEDIUM
EDK2 - Integer Overflow in Capsule Update Feature
CVSS 6.8
CVE-2014-4610 HIGH
FFmpeg < 0.10.14 - Remote Code Execution via Crafted Literal Run in LZO Decompression
CVSS 8.8
CVE-2014-4609 HIGH
libav < 0.8.13 - Remote Code Execution via Crafted Literal Run in LZO Decompression
CVSS 8.8
CVE-2014-9994 CRITICAL
Qualcomm Snapdragon Mobile SD 400 and SD 800 Firmware - Buffer Overflow via Integer Overflow
CVSS 9.8
CVE-2014-2885 HIGH
TrueCrypt 7.1a - Integer Overflow in EncryptedIoQueue.c and Ntdriver.c
CVSS 7.1
CVE-2014-5044 CRITICAL
libgfortran < 4.8 - Integer Overflow in Array Allocation
CVSS 9.8
CVE-2014-0143 HIGH
QEMU <2.0.0 - Denial of Service
CVSS 7.0
CVE-2014-9964 HIGH
Android - Integer Overflow in Debug Functionality
CVSS 7.8
Details
Vulnerabilities 3,210
Exploit Likelihood Medium