The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
3,177 vulnerabilities with CWE-190
CVE-2025-27918
CRITICAL
AnyDesk < 9.0.0 - Heap-Based Buffer Overflow via UDP Discovery Packet
CVSS 9.8
CVE-2025-47365
HIGH
Qualcomm Firmware - Memory Corruption via Large Input Data
CVSS 7.8
CVE-2025-12501
HIGH
GameMaker IDE < 2024.14.0 - Denial of Service via Integer Overflow in network_create_server()
CVSS 7.5
CVE-2025-62231
HIGH
X.Org Xwayland < 24.1.9 - Memory Corruption via XkbSetCompatMap Integer Overflow
CVSS 7.3
CVE-2025-11463
HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via XE File Parsing Integer Overflow
CVSS 7.8
CVE-2025-10924
HIGH
GIMP - Remote Code Execution via FF File Parsing Integer Overflow
CVSS 7.8
CVE-2025-10923
HIGH
GIMP - Remote Code Execution via WBMP File Parsing Integer Overflow
CVSS 7.8
CVE-2025-55067
HIGH
Veeder-Root TLS4B Automatic Tank Gauge System < 11.A - Denial of Service via Unix Time Overflow
CVSS 7.1
CVE-2025-54957
CRITICAL
Dolby UDC 4.5-4.13 - Integer Overflow to Out-of-Bounds Write in Evolution Data Processing
CVSS 9.8
CVE-2025-62171
MEDIUM
ImageMagick < 6.9.13-32 - Integer Overflow in BMP Decoder on 32-bit Systems
CVSS 5.9
CVE-2025-62496
HIGH
QuickJS < 2025-09-13 - Heap Out-of-Bounds Write via BigInt String Parsing Integer Overflow
CVSS 8.8
CVE-2025-39967
HIGH
Linux Kernel 4.4.235-4.5 - Integer Overflow in fbcon_do_set_font
CVSS 7.8
CVE-2025-61807
HIGH
Substance 3D Stager < 3.1.5 - Integer Overflow or Wraparound
CVSS 7.8
CVE-2025-61803
HIGH
Substance 3D Stager < 3.1.5 - Arbitrary Code Execution via Integer Overflow
CVSS 7.8
CVE-2025-61800
HIGH
Adobe Dimension < 4.1.5 - Integer Overflow or Wraparound
CVSS 7.8
CVE-2025-58715
HIGH
Microsoft Windows Speech < - Privilege Escalation
CVSS 8.8
CVE-2025-20722
MEDIUM
rdk-b - Local Information Disclosure via Integer Overflow in GNSS Driver
CVSS 5.5
CVE-2025-20710
HIGH
MediaTek Software Development Kit - Remote Escalation of Privilege via Integer Overflow in WLAN AP Driver
CVSS 8.8
CVE-2025-47351
HIGH
Qualcomm FastConnect and WCD/WCN/WSA Firmware - Memory Corruption via User Buffer Processing
CVSS 7.8
CVE-2025-39940
MEDIUM
Linux Kernel 2.6.31-6.12.49, 6.13.0-6.16.9 - Integer Overflow in dm-stripe stripe_io_hints
CVSS 5.5
CVE-2025-46819
MEDIUM
Redis < 6.2.20 - Authenticated Denial of Service via Lua Script
CVSS 6.3
CVE-2025-46817
HIGH
Redis < 6.2.20 - Authenticated Remote Code Execution via Lua Script Integer Overflow
CVSS 7.0
CVE-2025-11152
HIGH
Firefox < 143.0.3 - Buffer Overflow
CVSS 8.6
CVE-2025-59942
HIGH
Filecoin Go-f3 < 0.8.7 - Integer Overflow
CVSS 7.5
CVE-2025-51495
HIGH
Mongoose 7.5-7.17 - Integer Overflow in WebSocket Component
CVSS 7.5
Details
Vulnerabilities
3,177
Exploit Likelihood
Medium