CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,189 vulnerabilities with CWE-190
CVE-2023-52857 MEDIUM
Linux Kernel 5.13.12-6.5.11 - Integer Overflow in DRM Mediatek Component
CVSS 5.5
CVE-2023-52762 MEDIUM
Linux Kernel < 5.15.140 - Integer Overflow in virtio-blk DMA Size Calculation
CVSS 5.5
CVE-2023-52676 MEDIUM
Linux Kernel 5.10.33-5.11 - Integer Overflow in BPF Stack Limit Check
CVSS 5.5
CVE-2023-43530 MEDIUM
Qualcomm FastConnect and AQT1000/AR8035 Firmware - Memory Corruption in HLOS
CVSS 5.9
CVE-2023-44443 HIGH
GIMP < 2.10.36 - Remote Code Execution via PSP File Parsing Integer Overflow
CVSS 7.8
CVE-2023-41185 HIGH
Unified Automation UaGateway < 1.5.13.487 - DoS via Certificate Length Field Integer Overflow
CVSS 7.5
CVE-2023-40475 HIGH
GStreamer < 1.22.6 - Remote Code Execution via MXF File Parsing Integer Overflow
CVSS 8.8
CVE-2023-40474 HIGH
GStreamer < 1.22.6 - Remote Code Execution via MXF File Parsing Integer Overflow
CVSS 8.8
CVE-2023-38104 HIGH
GStreamer - Remote Code Execution via MDPR Chunk Integer Overflow
CVSS 8.8
CVE-2023-38103 HIGH
GStreamer - Remote Code Execution via MDPR Chunk Integer Overflow
CVSS 8.8
CVE-2023-37327 HIGH
GStreamer < 1.20.7 - Remote Code Execution via FLAC File Parsing Integer Overflow
CVSS 8.8
CVE-2023-47212 CRITICAL
stb_vorbis.c v1.22 - Heap-Based Buffer Overflow via Crafted OGG File
CVSS 9.8
CVE-2023-43550 HIGH
Qualcomm FastConnect and AR8035/CSRA6620/CSRA6640 Firmware - Memory Corruption in DHMS
CVSS 7.8
CVE-2023-6780 MEDIUM
glibc 2.37-2.38 - Heap-Based Buffer Overflow in __vsyslog_internal
CVSS 5.3
CVE-2023-40548 HIGH
shim < 15.8 - Heap-Based Buffer Overflow via PE Binary Parsing
CVSS 7.4
CVE-2023-52389 CRITICAL
POCO < 1.11.8 - Integer Overflow and Stack Buffer Overflow in UTF32Encoding
CVSS 9.8
CVE-2023-31034 MEDIUM
NVIDIA DGX A100 SBIOS - Buffer Overflow
CVSS 6.6
CVE-2023-49262 CRITICAL
Hongdian H8951-4G-ESP Firmware <= 2310271149 - Authentication Bypass via Cookie Overflow
CVSS 9.8
CVE-2023-52339 MEDIUM
libebml < 1.4.5 - Integer Overflow in MemIOCallback
CVSS 6.5
CVE-2023-28185 MEDIUM
iPadOS 15.0-15.7.4 - Denial of Service via Integer Overflow
CVSS 5.5
CVE-2023-41056 HIGH
Redis 7.0.9-7.0.14 and 7.2.0-7.2.3 - Remote Code Execution via Heap Overflow
CVSS 8.1
CVE-2023-47996 MEDIUM
FreeImage 3.18.0 - Integer Overflow in Exif.cpp::jpeg_read_exif_dir
CVSS 6.5
CVE-2023-47994 HIGH
FreeImage 3.18.0 - Integer Overflow in LoadPixelDataRLE4 Function
CVSS 8.8
CVE-2023-47992 HIGH
FreeImage 3.18.0 - Integer Overflow in FreeImageIO.cpp::_MemoryReadProc
CVSS 8.8
CVE-2023-39317 HIGH
GTKWave 3.3.115 - Arbitrary Code Execution via LXT2 num_dict_entries Integer Overflow
CVSS 7.8
Details
Vulnerabilities 3,189
Exploit Likelihood Medium