CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,210 vulnerabilities with CWE-190
CVE-2013-4391
systemd < 190 - Integer Overflow and Heap-Based Buffer Overflow via Large Journal Data Field
CVE-2013-2729 CRITICAL KEV
Adobe Reader/Acrobat <9.5.5, <10.1.7, <11.0.03 - RCE
CVSS 9.8
CVE-2013-1317
Microsoft Publisher <2003 SP3 - RCE
CVE-2013-2596 HIGH KEV
Linux kernel <3.8.9 - Privilege Escalation
CVSS 7.8
CVE-2013-2555
Adobe Flash Player <10.3.183.75-11.7.700.169 - RCE
CVE-2013-0899
opus < 1.0.2 - Denial of Service via Integer Overflow in Padding Implementation
CVE-2013-0891
Google Chrome <25.0.1364.97-25.0.1364.99 - DoS
CVE-2013-1591 CRITICAL
Redhat Enterprise Virtualization < 15.4 - Integer Overflow
CVSS 9.8
CVE-2013-0750
Firefox < 18.0 - Remote Code Execution via JavaScript String Concatenation
CVE-2012-5340 HIGH
SumatraPDF 2.1.1/MuPDF 1.0 - Memory Corruption
CVSS 7.8
CVE-2012-6706 CRITICAL
Sophos Threat Detection Engine < 3.37.2 - Remote Code Execution via Integer Overflow in VMSF_DELTA Processing
CVSS 9.8
CVE-2012-6703 HIGH
Linux Kernel 3.3-3.6 - Integer Overflow in ALSA Compress Offload Buffer Allocation
CVSS 7.8
CVE-2012-6701 HIGH
Linux Kernel < 3.4.1 - Integer Overflow in AIO iovec Handling
CVSS 7.8
CVE-2012-5143
Google Chrome <23.0.1271.97 - DoS
CVE-2012-5835
Mozilla Firefox < 17.0 - Remote Code Execution via WebGL Integer Overflow
CVE-2012-5054 HIGH KEV
Adobe Flash Player <11.4.402.265 - RCE
CVSS 8.8
CVE-2012-3481
GIMP < 2.8.0 - Integer Overflow and Heap-Based Buffer Overflow via GIF Image Properties
CVE-2012-3402
GIMP < 2.2.13 - Integer Overflow in PSD Plugin via Channels Header
CVE-2012-4025
Squashfs < 4.2 - Remote Code Execution via Crafted Block Log Field
CVE-2012-1867 HIGH
Windows XP/2003/Vista/7/2008 Local Privilege Escalation via TrueType Font Integer Overflow
CVSS 8.4
CVE-2012-2036
Adobe Flash Player < 11.2.202.235 and AIR < 3.2.0.2070 - Remote Code Execution via Integer Overflow
CVE-2012-1610 HIGH
ImageMagick < 6.7.6-4 - Denial of Service via EXIF Tag Integer Overflow
CVSS 7.5
CVE-2012-1185 HIGH
ImageMagick < 6.7.5 - Integer Overflow in EXIF IFD0 ResolutionUnit Tag
CVSS 7.8
CVE-2012-0044 HIGH
Linux Kernel < 3.1.5 - Integer Overflow in DRM Mode DirtyFB IOCTL
CVSS 7.8
CVE-2012-0038 MEDIUM
Linux Kernel < 3.1.9 - Denial of Service via Malformed ACL in xfs_acl_from_disk
CVSS 5.5
Details
Vulnerabilities 3,210
Exploit Likelihood Medium