CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,177 vulnerabilities with CWE-190
CVE-2024-45287 HIGH
FreeBSD 13.0-13.2 - Integer Overflow in libnv Structure Parsing
CVSS 7.5
CVE-2024-44981 MEDIUM
Linux Kernel 6.10-6.10.6 - Integer Overflow in shift_and_mask()
CVSS 5.5
CVE-2024-33035 HIGH
Qualcomm Multiple Firmware - Memory Corruption via Gralloc Metadata Size Calculation
CVSS 8.4
CVE-2024-28044 LOW
OpenHarmony < 4.1 - Denial of Service via Integer Overflow
CVSS 3.3
CVE-2024-45492 CRITICAL
libexpat < 2.6.3 - Integer Overflow in nextScaffoldPart
CVSS 9.8
CVE-2024-45491 CRITICAL
libexpat < 2.6.3 - Integer Overflow in dtdCopy
CVSS 9.8
CVE-2024-45490 HIGH
libexpat < 2.6.3 - Integer Overflow via Negative Length in XML_ParseBuffer
CVSS 7.5
CVE-2024-43890 MEDIUM
Linux Kernel - Integer Overflow in tracing_map next_elt Counter
CVSS 5.5
CVE-2024-30949 CRITICAL
newlib 4.3.0 - Remote Code Execution via Time Unit Scaling in _gettimeofday
CVSS 9.8
CVE-2024-43838 MEDIUM
Linux Kernel 6.9.8-6.10 - Integer Overflow in BPF Jump Offset Adjustment
CVSS 5.5
CVE-2024-34740 HIGH
Android - Integer Overflow in BinaryXmlSerializer
CVSS 7.8
CVE-2024-31333 HIGH
Android - Integer Overflow to Local Privilege Escalation in MMU AllocLevel
CVSS 7.8
CVE-2024-7867 MEDIUM
Xpdf < 4.05 - Integer Overflow and Divide-by-Zero via Page Box Coordinates
CVSS 6.2
CVE-2024-41851 HIGH
Adobe InDesign < 18.5.3 - Integer Overflow or Wraparound via Malicious File
CVSS 7.8
CVE-2024-21844 MEDIUM
Intel(R) CSME - Unauthenticated Denial of Service via Integer Overflow
CVSS 4.3
CVE-2024-41858 HIGH
Adobe InCopy < 18.5.2 - Integer Overflow or Wraparound via Malicious File
CVSS 7.8
CVE-2024-38215 HIGH
Windows Cloud Files Mini Filter Driver - Privilege Escalation
CVSS 7.8
CVE-2024-38144 HIGH
Kernel Streaming WOW Thunk Service Driver - Privilege Escalation
CVSS 8.8
CVE-2024-38128 HIGH
Windows Routing and Remote Access Service - Remote Code Execution
CVSS 8.8
CVE-2024-33024 HIGH
Qualcomm AR8035 Firmware - Denial of Service via Malformed ML IE Length Field
CVSS 7.5
CVE-2024-33022 HIGH
Qualcomm AR8035 Firmware - Memory Corruption via HGSL Driver Integer Overflow
CVSS 8.4
CVE-2024-42223 MEDIUM
Linux Kernel Integer Overflow in TDA10048 DVB Frontend
CVSS 5.5
CVE-2024-42136 HIGH
Linux Kernel - Integer Overflow in CDROM Last Media Change Check
CVSS 7.8
CVE-2024-42131 MEDIUM
Linux Kernel Integer Overflow in Dirty Throttling Logic
CVSS 4.4
CVE-2024-40784 MEDIUM
iPadOS < 16.7.9 - Integer Overflow via Maliciously Crafted File
CVSS 5.5
Details
Vulnerabilities 3,177
Exploit Likelihood Medium