CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,210 vulnerabilities with CWE-190
CVE-2011-3631 HIGH
Hardlink <0.1.2 - Memory Corruption
CVSS 8.8
CVE-2011-1298 HIGH
Blink < M11 - Integer Overflow in WebCore::GraphicsContext::fillRect
CVSS 7.5
CVE-2011-4093
libnet6 <1.3.14 - Privilege Escalation
CVE-2011-4097 MEDIUM
Linux Kernel < 3.1.8 - Denial of Service via Integer Overflow in oom_badness
CVSS 5.5
CVE-2011-3065
Chrome < 18.0.1025.142 - Integer Overflow in Skia
CVE-2011-3045 HIGH
Google Chrome < 17.0.963.83 - Remote Code Execution via Crafted PNG File
CVSS 8.8
CVE-2011-3026
Google Chrome < 17.0.963.56 - Integer Overflow in libpng
CVE-2011-3015
Google Chrome < 17.0.963.56 - Integer Overflow in PDF Codecs
CVE-2011-4374
Adobe Reader 9.x < 9.4.6 - Remote Code Execution via Integer Overflow
CVE-2011-2013 CRITICAL
Microsoft Windows - Buffer Overflow
CVSS 9.8
CVE-2011-2829
Google Chrome < 13.0.782.215 - Integer Overflow via Uniform Arrays
CVE-2011-0211
QuickTime < 7.7.0 - Remote Code Execution via Crafted Movie File
CVE-2011-0209
QuickTime < 7.7.0 - Remote Code Execution via Crafted RIFF WAV File
CVE-2011-1823 HIGH KEV
Android <2.3.4 - Privilege Escalation
CVSS 7.8
CVE-2011-1178
GIMP < 2.7.0 - Integer Overflow and Heap-Based Buffer Overflow via Crafted PCX Image
CVE-2011-1800
Google Chrome < 11.0.696.71 - Integer Overflow in SVG Filters
CVE-2011-1745
Linux kernel <2.6.38.5 - Privilege Escalation
CVE-2011-1437
Google Chrome < 11.0.696.57 - Integer Overflow in Float Rendering
CVE-2011-1593
Linux Kernel < 2.6.38.4 - Denial of Service via getdents or readdir System Call
CVE-2011-0663 HIGH
Microsoft JScript and VBScript 5.6-5.8 - Remote Code Execution via Integer Overflow
CVSS 8.8
CVE-2011-1121
Google Chrome < 9.0.597.107 - Integer Overflow via TEXTAREA Element
CVE-2010-4653 MEDIUM
poppler < 0.16.3 - Integer Overflow in Font CharCode Parsing
CVSS 6.5
CVE-2010-4649
Linux Kernel < 2.6.37 - Integer Overflow in ib_uverbs_poll_cq
CVE-2010-3865
Linux Kernel < 2.6.36 - Integer Overflow and Buffer Overflow in RDS RDMA Pages
CVE-2010-4160
Linux Kernel < 2.6.36.2 - Integer Overflow in PPPoL2TP and IPoL2TP via Crafted Sendto Call
Details
Vulnerabilities 3,210
Exploit Likelihood Medium