CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,177 vulnerabilities with CWE-190
CVE-2025-27918 CRITICAL
AnyDesk < 9.0.0 - Heap-Based Buffer Overflow via UDP Discovery Packet
CVSS 9.8
CVE-2025-47365 HIGH
Qualcomm Firmware - Memory Corruption via Large Input Data
CVSS 7.8
CVE-2025-12501 HIGH
GameMaker IDE < 2024.14.0 - Denial of Service via Integer Overflow in network_create_server()
CVSS 7.5
CVE-2025-62231 HIGH
X.Org Xwayland < 24.1.9 - Memory Corruption via XkbSetCompatMap Integer Overflow
CVSS 7.3
CVE-2025-11463 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via XE File Parsing Integer Overflow
CVSS 7.8
CVE-2025-10924 HIGH
GIMP - Remote Code Execution via FF File Parsing Integer Overflow
CVSS 7.8
CVE-2025-10923 HIGH
GIMP - Remote Code Execution via WBMP File Parsing Integer Overflow
CVSS 7.8
CVE-2025-55067 HIGH
Veeder-Root TLS4B Automatic Tank Gauge System < 11.A - Denial of Service via Unix Time Overflow
CVSS 7.1
CVE-2025-54957 CRITICAL
Dolby UDC 4.5-4.13 - Integer Overflow to Out-of-Bounds Write in Evolution Data Processing
CVSS 9.8
CVE-2025-62171 MEDIUM
ImageMagick < 6.9.13-32 - Integer Overflow in BMP Decoder on 32-bit Systems
CVSS 5.9
CVE-2025-62496 HIGH
QuickJS < 2025-09-13 - Heap Out-of-Bounds Write via BigInt String Parsing Integer Overflow
CVSS 8.8
CVE-2025-39967 HIGH
Linux Kernel 4.4.235-4.5 - Integer Overflow in fbcon_do_set_font
CVSS 7.8
CVE-2025-61807 HIGH
Substance 3D Stager < 3.1.5 - Integer Overflow or Wraparound
CVSS 7.8
CVE-2025-61803 HIGH
Substance 3D Stager < 3.1.5 - Arbitrary Code Execution via Integer Overflow
CVSS 7.8
CVE-2025-61800 HIGH
Adobe Dimension < 4.1.5 - Integer Overflow or Wraparound
CVSS 7.8
CVE-2025-58715 HIGH
Microsoft Windows Speech < - Privilege Escalation
CVSS 8.8
CVE-2025-20722 MEDIUM
rdk-b - Local Information Disclosure via Integer Overflow in GNSS Driver
CVSS 5.5
CVE-2025-20710 HIGH
MediaTek Software Development Kit - Remote Escalation of Privilege via Integer Overflow in WLAN AP Driver
CVSS 8.8
CVE-2025-47351 HIGH
Qualcomm FastConnect and WCD/WCN/WSA Firmware - Memory Corruption via User Buffer Processing
CVSS 7.8
CVE-2025-39940 MEDIUM
Linux Kernel 2.6.31-6.12.49, 6.13.0-6.16.9 - Integer Overflow in dm-stripe stripe_io_hints
CVSS 5.5
CVE-2025-46819 MEDIUM
Redis < 6.2.20 - Authenticated Denial of Service via Lua Script
CVSS 6.3
CVE-2025-46817 HIGH
Redis < 6.2.20 - Authenticated Remote Code Execution via Lua Script Integer Overflow
CVSS 7.0
CVE-2025-11152 HIGH
Firefox < 143.0.3 - Buffer Overflow
CVSS 8.6
CVE-2025-59942 HIGH
Filecoin Go-f3 < 0.8.7 - Integer Overflow
CVSS 7.5
CVE-2025-51495 HIGH
Mongoose 7.5-7.17 - Integer Overflow in WebSocket Component
CVSS 7.5
Details
Vulnerabilities 3,177
Exploit Likelihood Medium