CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,198 vulnerabilities with CWE-190
CVE-2023-33022 HIGH
Qualcomm 315 5G IoT Modem Firmware - Memory Corruption via HLOS IOCTL Calls
CVSS 8.4
CVE-2023-33018 HIGH
Qualcomm 315 5G IoT Modem Firmware - Memory Corruption via UIM Diag Command
CVSS 7.8
CVE-2023-28588 HIGH
Qualcomm Bluetooth Host - Denial of Service via RFC Slot Allocation
CVSS 7.5
CVE-2023-6345 CRITICAL KEV
Google Chrome <119.0.6045.199 - Sandbox Escape
CVSS 9.6
CVE-2023-4398 HIGH
Zyxel ATP/USG FLEX/USG20(W)-VPN <5.37 - DoS
CVSS 7.5
CVE-2023-4424 HIGH
Zephyr < 3.4.0 - Buffer Overflow via Malformed BLE Advertising Packet
CVSS 8.3
CVE-2023-48237 LOW
vim < 9.0.2112 - Integer Overflow in Operator Pending Mode Line Shift
CVSS 2.8
CVE-2023-48236 LOW
vim < 9.0.2111 - Integer Overflow via z= Command
CVSS 2.8
CVE-2023-48235 LOW
vim < 9.0.2110 - Integer Overflow in Relative Ex Address Parsing
CVSS 2.8
CVE-2023-48234 LOW
vim < 9.0.2109 - Integer Overflow via Normal Mode z Command Count
CVSS 2.8
CVE-2023-48233 LOW
vim < 9.0.2108 - Integer Overflow via :s Command Count
CVSS 2.8
CVE-2023-22305 MEDIUM
Intel Aptio V UEFI Firmware Integrator Tools - Authenticated Denial of Service via Integer Overflow
CVSS 6.5
CVE-2023-36401 HIGH
Microsoft Remote Registry Service - RCE
CVSS 7.2
CVE-2023-36395 HIGH
Windows Deployment Services - Denial of Service via Integer Overflow
CVSS 7.5
CVE-2023-4949 HIGH
GRUB < 0.97 - Memory Corruption via XFS File System Implementation
CVSS 8.1
CVE-2023-4295 HIGH
ARM Mali GPU Kernel Driver r41p0 through r43p0 and Valhall GPU Kernel Driver r29p0 through r42p0 - Use-After-Free
CVSS 7.8
CVE-2023-5849 HIGH
Google Chrome < 119.0.6045.105 - Integer Overflow in USB via Crafted HTML Page
CVSS 8.8
CVE-2023-21375 HIGH
Android < 14.0 - Integer Underflow to Out-of-Bounds Write in Sysproxy
CVSS 7.8
CVE-2023-21371 MEDIUM
Android < 14.0 - Integer Overflow to Out-of-Bounds Write in Secure Element
CVSS 6.7
CVE-2023-21370 MEDIUM
Android < 14.0 - Integer Overflow to Out-of-Bounds Write in Security Element API
CVSS 6.7
CVE-2023-46246 MEDIUM
vim < 9.0.2068 - Use-After-Free via Integer Overflow in History Command
CVSS 4.0
CVE-2023-42295 HIGH
OpenImageIO 2.4.12.0 - Remote Code Execution and Denial of Service via read_rle_image Function
CVSS 8.8
CVE-2023-45681 HIGH
stb_vorbis.c - Heap Buffer Overflow via Integer Overflow in start_decoder
CVSS 7.3
CVE-2023-3487 HIGH
Silicon Labs Gecko Bootloader < 4.3.1 - Integer Overflow in Storage Slot Access
CVSS 7.7
CVE-2023-38127 HIGH
Justsystems Easy Postcard Max - Integer Overflow
CVSS 7.8
Details
Vulnerabilities 3,198
Exploit Likelihood Medium