CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,189 vulnerabilities with CWE-190
CVE-2024-21836 HIGH
llama.cpp - Heap-Based Buffer Overflow via GGUF Library Header.n_tensors
CVSS 8.8
CVE-2024-21825 HIGH
llama.cpp - Heap-Based Buffer Overflow in GGUF Library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING Parsing
CVSS 8.8
CVE-2024-25366 MEDIUM
libiec61859 <1.4.0 - Buffer Overflow
CVSS 6.2
CVE-2024-21812 CRITICAL
libbiosig 2.5.0 and Master Branch - Integer Overflow in sopen_FAMOS_read
CVSS 9.8
CVE-2024-1633 LOW
Renesas ARM Trusted Firmware - Integer Overflow in BL2 Image Certificate Parsing
CVSS 2.0
CVE-2024-1580 MEDIUM
dav1d < 1.4.0 - Integer Overflow in AV1 Decoder
CVSS 5.9
CVE-2024-20730 HIGH
Acrobat Reader <20.005.30539, 23.008.20470 - RCE
CVSS 7.8
CVE-2024-21420 HIGH
Windows 10 1507-22H2 - Remote Code Execution via WDAC OLE DB Provider Integer Overflow
CVSS 8.8
CVE-2024-21379 HIGH
Microsoft Word - Remote Code Execution via Integer Overflow
CVSS 7.8
CVE-2024-21372 HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2008-2022 - Remote Code Execution via OLE Integer Overflow
CVSS 8.8
CVE-2024-21350 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-23H2 - Remote Code Execution via WDAC OLE DB Provider Integer Overflow
CVSS 8.8
CVE-2024-24857 MEDIUM
Linux kernel < 3.19.8 and >=v4.0-rc1 <v6.8-rc2 - Denial of Service via Bluetooth Connection Info Race Condition
CVSS 4.6
CVE-2024-20016 MEDIUM
Android - Integer Overflow to Out-of-Bounds Write in GED
CVSS 4.4
CVE-2024-21851 LOW
OpenHarmony < 3.2.4 - Heap Overflow via Integer Overflow
CVSS 2.9
CVE-2024-21845 LOW
OpenHarmony < 3.2.4 - Heap Overflow via Integer Overflow
CVSS 2.9
CVE-2024-23775 HIGH
Mbed TLS 2.x < 2.28.7 and 3.x < 3.5.2 - Denial of Service via mbedtls_x509_set_extension()
CVSS 7.5
CVE-2024-22861 HIGH
FFmpeg < 6.1 - Denial of Service via avcodec/osq Module Integer Overflow
CVSS 7.5
CVE-2024-22862 CRITICAL
FFmpeg < 6.1 - Remote Code Execution via JJPEG XL Parser Integer Overflow
CVSS 9.8
CVE-2024-22860 CRITICAL
FFmpeg < 6.1 - Remote Code Execution via JPEG XL Animation Decoder Integer Overflow
CVSS 9.8
CVE-2024-23307 MEDIUM
Linux Kernel 4.1-6.1.84 - Integer Overflow in RAID5 Module
CVSS 4.4
CVE-2024-23851 MEDIUM
Linux Kernel < 6.7.1 - Denial of Service via Missing Data Size Check in dm-ioctl
CVSS 5.5
CVE-2024-22211 LOW
FreeRDP < 2.11.5 - Heap-Buffer Overflow via RDPGFX_RESET_GRAPHICS_PDU
CVSS 3.7
CVE-2024-20698 HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2024-20654 HIGH
Microsoft ODBC Driver - Remote Code Execution via Integer Overflow
CVSS 8.0
CVE-2024-21646 CRITICAL
Azure uAMQP < 2024-01-01 - Remote Code Execution via Crafted Binary Type Data
CVSS 9.8
Details
Vulnerabilities 3,189
Exploit Likelihood Medium