CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,177 vulnerabilities with CWE-190
CVE-2025-0678 HIGH
GRUB2 < 2.12 - Integer Overflow to Heap-Based Buffer Overflow in Squash4 Filesystem Module
CVSS 7.8
CVE-2025-20653 MEDIUM
Android - Local Information Disclosure via Integer Overflow in da
CVSS 6.5
CVE-2025-21748 MEDIUM
Linux Kernel 5.15-6.13.2 - Integer Overflow in ksmbd ipc_msg_alloc
CVSS 5.5
CVE-2025-21736 MEDIUM
Linux Kernel - Integer Overflow in nilfs2 fiemap Block Calculation
CVSS 5.5
CVE-2025-21711 MEDIUM
Linux Kernel - Integer Overflow in rose_setsockopt
CVSS 5.5
CVE-2025-0838 CRITICAL
Abseil-cpp < 20250127.0 - Heap Buffer Overflow via Integer Overflow in Hash Container Sized Constructors
CVSS 9.8
CVE-2025-21369 HIGH
Windows 10/11, Server 2008 - RCE via Digest Auth Integer Overflow
CVSS 8.8
CVE-2025-0302 MEDIUM
OpenHarmony 4.1.0-4.1.2 - Denial of Service via Integer Overflow
CVSS 5.5
CVE-2025-24156 HIGH
macOS < 13.7.3, < 14.7.3, < 15.3 - Privilege Escalation via Integer Overflow
CVSS 7.8
CVE-2025-21382 HIGH
Windows Graphics Component - Elevation of Privilege via Integer Overflow
CVSS 7.8
CVE-2025-21338 HIGH
Microsoft Office - Remote Code Execution via GDI+ Integer Overflow
CVSS 7.8
CVE-2025-21244 HIGH
Windows Telephony Service - Remote Code Execution via Integer Overflow
CVSS 8.8
CVE-2025-21243 HIGH
Windows Telephony Service - Remote Code Execution via Integer Overflow
CVSS 8.8
CVE-2025-21172 HIGH
.NET and Visual Studio - Remote Code Execution via Integer Overflow
CVSS 7.5
CVE-2025-23022 MEDIUM
FreeType 2.8.1 - Integer Overflow in cf2_doFlex
CVSS 4.0
CVE-2025-23016 CRITICAL
FastCGI fcgi 2.0.0-2.4.4 - Heap-Based Buffer Overflow via Crafted nameLen or valueLen in IPC Socket
CVSS 9.3
CVE-2024-36320 HIGH
AMD Ryzen 4000 Series Mobile Processors with Radeon Graphics - Integer Overflow in atihdwt6.sys
CVE-2024-36316 MEDIUM
AMD Ryzen 6000 and 7035 Series Processors - Denial of Service via Integer Overflow in Graphics Driver
CVSS 5.5
CVE-2024-38805 MEDIUM
EDK2 < edk2-stable202502 - Denial of Service via Integer Overflow
CVSS 6.3
CVE-2024-58263 LOW
cosmwasm-std 1.3.0-1.4.3 - Integer Overflow in Contract Calculations
CVSS 3.7
CVE-2024-52035 HIGH
catdoc 0.95 - Heap-Based Memory Corruption via OLE Document File Allocation Table Parser
CVSS 8.4
CVE-2024-23337 MEDIUM
jqlang/jq <= 1.7.1 - Denial of Service via Integer Overflow
CVSS 4.3
CVE-2024-45575 HIGH
Qualcomm FastConnect 6900 Firmware - Memory Corruption via Camera Kernel Device Attachment
CVSS 7.8
CVE-2024-36337 HIGH
AMD Ryzen AI Software >=1.3 - Integer Overflow in NPU Driver
CVSS 7.9
CVE-2024-36336 HIGH
AMD Ryzen AI Software >=1.3 - Integer Overflow in NPU Driver
CVSS 7.9
Details
Vulnerabilities 3,177
Exploit Likelihood Medium