CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,329 vulnerabilities with CWE-190
CVE-2026-24889 MEDIUM
soroban-sdk < 25.0.2 - Integer Overflow in Bytes::slice, Vec::slice, and Prng::gen_range
CVSS 5.3
CVE-2026-24875 HIGH
yoyofr modizer <4.1.1 - Buffer Overflow
CVSS 7.8
CVE-2026-24830 CRITICAL
Ralim IronOS <v2.23-rc2 - Buffer Overflow
CVSS 9.8
CVE-2026-24814 CRITICAL
swoole-src <6.0.2 - Buffer Overflow
CVE-2026-24808 HIGH
RawTherapee <5.11 - Buffer Overflow
CVE-2026-1464 MEDIUM
MuntashirAkon AppManager <4.0.4 - Buffer Overflow
CVE-2026-24403 HIGH
iccDEV <2.3.1.1 - Memory Corruption
CVSS 7.1
CVE-2026-0988 LOW
RHEL 6-10 & Hardened Images - DoS via Integer Overflow in g_buffered_input_stream_peek
CVSS 3.7
CVE-2026-23876 HIGH
ImageMagick <7.1.2-13 & <6.9.13-38 - Buffer Overflow
CVSS 8.1
CVE-2026-23833 HIGH
ESPHome 2025.9.0-2025.12.6 - Unauthenticated Denial of Service via API Protobuf Decoder Integer Overflow
CVSS 7.5
CVE-2026-0861 HIGH
GNU C Library 2.30-2.42 - Integer Overflow via Large Alignment in memalign Suite
CVSS 8.4
CVE-2026-0880 HIGH
Firefox < 115.32.0 and 140.7-147.0 - Sandbox Escape via Graphics Integer Overflow
CVSS 8.8
CVE-2026-22801 MEDIUM
libpng 1.6.26-1.6.53 - Heap Buffer Over-read via Negative Row Stride
CVSS 6.8
CVE-2026-21689 MEDIUM
iccDEV < 2.3.1.2 - Type Confusion in CIccProfileXml::ParseBasic()
CVSS 6.5
CVE-2026-21688 HIGH
iccDEV < 2.3.1.2 - Type Confusion in SIccCalcOp::ArgsPushed()
CVSS 8.8
CVE-2026-21486 HIGH
iccdev < 2.3.1.2 - Heap-based Buffer Overflow in CIccSparseMatrix
CVSS 7.8
CVE-2026-21485 HIGH
iccdev < 2.3.1.2 - Out-of-bounds Read
CVSS 8.8
CVE-2026-21673 HIGH
iccDEV < 2.3.1.1 - Integer Overflow in CIccXmlArrayType::ParseTextCountNum()
CVSS 7.8
CVE-2025-55647 MEDIUM
GPAC MP4Box 2.4 - Denial of Service via Crafted MP4 File
CVSS 5.5
CVE-2025-14098 HIGH
Avira antivirus engine heap buffer OOB write when scanning a malformed MS-DOS executable file
CVSS 7.8
CVE-2025-66280 HIGH
QNAP Systems - QTS, QuTS Hero
CVSS 7.2
CVE-2025-48595 HIGH KEV
Google Android - Integer Overflow or Wraparound
CVSS 8.4
CVE-2025-47392 HIGH
Integer Overflow or Wraparound in GPS
CVSS 8.8
CVE-2025-43238 MEDIUM
macOS < 13.7.7, < 14.7.7, < 15.6 - Denial of Service via Integer Overflow
CVSS 6.2
CVE-2025-46597 HIGH
Bitcoin Core 0.13.0-29.x - Memory Corruption
CVSS 7.5
Details
Vulnerabilities 3,329
Exploit Likelihood Medium