CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,198 vulnerabilities with CWE-190
CVE-2023-22666 HIGH
Qualcomm APQ8009 Firmware - Memory Corruption in Audio via Modified AMRWBPLUS Clips
CVSS 8.4
CVE-2023-38698 MEDIUM
Ethereum Name Service - Info Disclosure
CVSS 4.9
CVE-2023-3107 HIGH
FreeBSD - Denial of Service via IPv6 Fragment Reassembly Integer Overflow
CVSS 7.5
CVE-2023-38560 MEDIUM
Ghostscript - Denial of Service via PCL Glyph Name Integer Overflow
CVSS 5.5
CVE-2023-36495 CRITICAL
iPadOS < 15.7.8 - Integer Overflow to Kernel Code Execution
CVSS 9.8
CVE-2023-38403 HIGH
iperf3 < 3.14 - Integer Overflow via Crafted Length Field
CVSS 7.5
CVE-2023-21241 HIGH
Android - Integer Overflow to Out-of-Bounds Write in rw_i93.cc
CVSS 7.8
CVE-2023-35364 HIGH
Windows Kernel - Elevation of Privilege via Integer Overflow
CVSS 8.8
CVE-2023-35341 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Information Disclosure via DirectMusic Integer Overflow
CVSS 6.2
CVE-2023-35315 HIGH
Windows Layer-2 Bridge Network Driver - Remote Code Execution via Integer Overflow
CVSS 8.8
CVE-2023-35312 HIGH
Windows VOLSNAP.SYS - Elevation of Privilege via Integer Overflow
CVSS 7.8
CVE-2023-32051 HIGH
Raw Image Extension < 2.0.61662.0 - Remote Code Execution
CVSS 7.8
CVE-2023-22667 HIGH
Qualcomm 315 5G IoT Firmware - Memory Corruption via Ion Buffer Allocation
CVSS 8.4
CVE-2023-20756 MEDIUM
Android - Integer Overflow to Out-of-Bounds Write in keyinstall
CVSS 6.7
CVE-2023-20755 MEDIUM
Android - Integer Overflow to Out-of-Bounds Write in keyinstall
CVSS 6.7
CVE-2023-20693 HIGH
Yocto - Denial of Service via WLAN Firmware Exception
CVSS 7.5
CVE-2023-20691 HIGH
Yocto - Remote Denial of Service via Integer Overflow
CVSS 7.5
CVE-2023-20690 HIGH
Yocto - Remote Denial of Service via Integer Overflow
CVSS 7.5
CVE-2023-20689 HIGH
Yocto - Remote Denial of Service via Integer Overflow
CVSS 7.5
CVE-2023-25516 HIGH
NVIDIA GPU Display Driver < 11.12 - Integer Overflow Leading to Information Disclosure and Denial of Service
CVSS 7.1
CVE-2023-21193 HIGH
Android 13 - Remote Information Disclosure via Integer Overflow in VideoFrame
CVSS 7.5
CVE-2023-25004 HIGH
Autodesk Alias >=2023 <2023.1.1 - Remote Code Execution via Malicious pskernel.dll File
CVSS 7.8
CVE-2023-32434 HIGH KEV
iPadOS < 15.7.7 - Integer Overflow to Kernel Code Execution
CVSS 7.8
CVE-2023-28295 HIGH
Microsoft Publisher - Remote Code Execution via Integer Overflow
CVSS 7.8
CVE-2023-34454 MEDIUM
snappy-java < 1.1.10.1 - Integer Overflow via Unchecked Multiplication in Compress Functions
CVSS 5.9
Details
Vulnerabilities 3,198
Exploit Likelihood Medium