CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,210 vulnerabilities with CWE-190
CVE-2009-0586
gstreamer < 0.10.23 - Remote Code Execution via Crafted COVERART Tag
CVE-2008-4864
Python 1.5.2-2.5.1 - Integer Overflow in imageop.c crop Function
CVE-2008-4309 HIGH
net-snmp 5.2-5.2.5, 5.3-5.3.2.2, 5.4-5.4.2 - Denial of Service via SNMP GETBULK Request
CVSS 7.5
CVE-2008-4036 HIGH
Microsoft Windows XP-Server 2008 - Privilege Escalation
CVSS 8.4
CVE-2008-4019
Microsoft Excel - Remote Code Execution via REPT Function Integer Overflow
CVE-2008-1446
Internet Information Services 5.0-7.0 - Authenticated Remote Code Execution via IPP Integer Overflow
CVE-2008-2315
Python < 2.5.2 - Integer Overflow in Multiple Modules
CVE-2008-3143
Python < 2.5.2 - Integer Overflow in Multiple Modules
CVE-2008-3144
Python < 2.5.2 - Integer Overflow in PyOS_vsnprintf String Formatting
CVE-2008-2826
Linux Kernel < 2.6.25.9 - Denial of Service via SCTP addr_num Integer Overflow
CVE-2008-2663
Ruby < 1.8.4, 1.8.5 < p231, 1.8.6 < p230, 1.8.7 < p22 - Integer Overflow in rb_ary_store
CVE-2008-1679
Python < 2.5.3 - Integer Overflow in imageop.c
CVE-2008-1083 HIGH
Microsoft Windows - Buffer Overflow
CVSS 8.1
CVE-2008-1374
CUPS < 1.3.11 - Remote Code Execution via pdftops Filter Integer Overflow
CVE-2007-6353
exiv2 < 0.16 - Remote Code Execution via Crafted EXIF File
CVE-2007-4965
Python < 2.5.1 - Denial of Service and Information Disclosure via Integer Overflow in imageop Module
CVE-2007-2834
OpenOffice.org < 2.3 - Remote Code Execution via TIFF Parser Integer Overflow
CVE-2007-2223
Microsoft XML Core Services 3.0-6.0 - Remote Code Execution via substringData Integer Overflow
CVE-2007-3387
CUPS - Remote Code Execution via Crafted PDF File
CVE-2007-2949
Gimp 2.2.15 - Remote Code Execution
CVE-2007-0221
Microsoft Exchange Server 2000 SP3 - Denial of Service via IMAP Literal Processing
CVE-2007-1383 CRITICAL
PHP 4 - Remote Code Execution via 16-bit Reference Counter Overflow
CVSS 9.8
CVE-2006-4519
GIMP < 2.2.16 - Remote Code Execution via Integer Overflow in Image Loader Plug-ins
CVE-2006-5937
Grisoft AVG Anti-Virus - Remote Code Execution via Crafted CAB or RAR Archives
CVE-2006-3198
Opera <8.54 - Remote Code Execution
Details
Vulnerabilities 3,210
Exploit Likelihood Medium