CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,189 vulnerabilities with CWE-190
CVE-2024-37323 HIGH
SQL Server 2016/2017/2019/2022 Remote Code Execution via Integer Overflow
CVSS 8.8
CVE-2024-26184 MEDIUM
Windows Secure Boot Security Feature Bypass via Integer Overflow
CVSS 6.8
CVE-2024-21428 HIGH
SQL Server 2016-2022 Remote Code Execution via Integer Overflow
CVSS 8.8
CVE-2024-1305 CRITICAL
tap-windows6 < 9.26.0 - Integer Overflow via Write Operation Size Check
CVSS 9.8
CVE-2024-23372 HIGH
Qualcomm FastConnect and Flight RB5 5G Platform Firmware - Memory Corruption via GPU Memory Allocation IOCTL
CVSS 8.4
CVE-2024-38661 MEDIUM
Linux Kernel - Integer Overflow in AP Internal Function modify_bitmap()
CVSS 5.5
CVE-2024-38624 MEDIUM
Linux Kernel 5.15-5.15.160, 5.16-6.1.92, 6.2-6.6.32, 6.7-6.9.3 - Integer Overflow in NTFS3 VBO Calculation
CVSS 5.5
CVE-2024-37356 MEDIUM
Linux Kernel - Integer Overflow in DCTCP Alpha Update via Shift-Out-of-Bounds
CVSS 5.5
CVE-2024-37305 HIGH
oqs-provider < 0.6.1 - Buffer Overflow via DECODE_UINT32 Length Handling
CVSS 8.2
CVE-2024-32913 CRITICAL
Android - Remote Code Execution via Integer Overflow in wl_notify_rx_mgmt_frame
CVSS 9.8
CVE-2024-29784 HIGH
Lwis Periodic Io - Privilege Escalation
CVSS 7.8
CVE-2024-30072 HIGH
Microsoft Event Trace Log File Parsing - RCE
CVSS 7.8
CVE-2024-30067 MEDIUM
Windows 10/11, Server 2012-2022 Elevation of Privilege via Winlogon Integer Overflow
CVSS 5.5
CVE-2024-30064 HIGH
Windows Kernel - Privilege Escalation
CVSS 8.8
CVE-2024-27833 HIGH
tvOS <17.5-iPadOS <16.7.8-visionOS <1.2-Safari <17.5-iOS <17.5 - RCE
CVSS 8.8
CVE-2024-36968 MEDIUM
Linux Kernel - Integer Overflow and Divide-by-Zero in Bluetooth L2CAP Flow Control
CVSS 6.5
CVE-2024-5171 CRITICAL
libaom 1.0.0-3.8.9 - Integer Overflow via img_alloc_helper
CVSS 9.8
CVE-2024-36121 MEDIUM
Netty OHTTP Codec 0.0.3-0.0.11 - Nonce Reuse via Sequence Overflow
CVSS 5.9
CVE-2024-5197 CRITICAL
libvpx < 1.14.1 - Integer Overflow via vpx_img_alloc or vpx_img_wrap
CVSS 9.1
CVE-2024-36948 MEDIUM
Linux Kernel 6.8-6.8.9 - Integer Overflow in Xe Migration Multiplication
CVSS 5.5
CVE-2024-36918 MEDIUM
Linux Kernel 5.16-6.1.91, 6.2-6.6.31, 6.7-6.8.10 - Integer Overflow via Bloom Filter Map Value Size
CVSS 5.5
CVE-2024-36917 MEDIUM
Linux Kernel 2.6.28-6.1.90, 6.2.0-6.6.30, 6.7.0-6.8.9 - Integer Overflow in blk_ioctl_discard()
CVSS 5.5
CVE-2024-30212 HIGH
MPLAB Harmony 3 Core Module 3.0.0-3.13.3 - Unauthenticated Arbitrary Memory Read and Write via SCSI READ(10) Command
CVE-2024-4453 HIGH
GStreamer EXIF Parser - Remote Code Execution via Integer Overflow
CVSS 7.8
CVE-2024-35905 HIGH
Linux Kernel - Use-After-Free in BPF Stack Access Size Validation
CVSS 7.8
Details
Vulnerabilities 3,189
Exploit Likelihood Medium