CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,200 vulnerabilities with CWE-190
CVE-2022-28195 MEDIUM
NVIDIA Jetson Linux < 32.7.2 - Integer Overflow in Cboot ext4_read_file Function
CVSS 5.7
CVE-2022-20684 HIGH
Cisco IOS XE Wireless Controller - DoS
CVSS 7.4
CVE-2022-28041 MEDIUM
stb_image.h v2.27 - Denial of Service via Integer Overflow in stbi__jpeg_decode_block_prog_dc
CVSS 6.5
CVE-2022-21154 HIGH
Leadtools 22 - Integer Overflow in fltSaveCMP via Crafted BMP File
CVSS 7.8
CVE-2022-24845 HIGH
vyperlang/vyper < 0.3.2 - Integer Overflow via Unvalidated int128 Return
CVSS 8.8
CVE-2022-27833 MEDIUM
Android DSP Driver - Integer Overflow to Out-of-Bounds Write
CVSS 4.4
CVE-2022-20075 MEDIUM
Android - Integer Overflow to Out-of-Bounds Write in GED
CVSS 6.7
CVE-2022-20069 MEDIUM
Preloader (usb) - Local Privilege Escalation
CVSS 6.6
CVE-2022-27148 MEDIUM
GPAC mp4box < 2.0.0 - Integer Overflow
CVSS 5.5
CVE-2022-24795 MEDIUM
yajl-ruby < 1.4.2 - Integer Overflow to Heap Memory Corruption in yajl_buf.c
CVSS 5.9
CVE-2022-0608 HIGH
Google Chrome <98.0.4758.102 - Heap Corruption
CVSS 8.8
CVE-2022-0998 HIGH
Linux Kernel >=5.7 <5.10.88 - Integer Overflow in virtio Device Driver
CVSS 7.8
CVE-2022-21821 HIGH
NVIDIA CUDA Toolkit < 11.6.2 - Integer Overflow in cuobjdump
CVSS 7.8
CVE-2022-23884 CRITICAL
Mojang Bedrock Dedicated Server <1.18.2 - Code Injection
CVSS 9.8
CVE-2022-1036 HIGH
microweber < 1.2.12 - Integer Overflow via Long Password
CVSS 7.5
CVE-2022-0968 MEDIUM
microweber < 1.2.12 - Denial of Service via Large Input in First & Last Name Field
CVSS 5.5
CVE-2022-0961 MEDIUM
microweber < 1.2.12 - Denial of Service via Post Title Input Field
CVSS 5.5
CVE-2022-23943 CRITICAL
Apache HTTP Server <2.4.52 - Memory Corruption
CVSS 9.8
CVE-2022-22721 CRITICAL
Apache HTTP Server < 2.4.52 - Integer Overflow via Large Request Body Handling
CVSS 9.1
CVE-2022-0913 HIGH
microweber < 1.2.11 and < 1.2.12 - Integer Overflow or Wraparound
CVSS 7.5
CVE-2022-0204 HIGH
bluez < 5.63 - Denial of Service via Heap Overflow
CVSS 8.8
CVE-2022-26495 CRITICAL
network_block_device < 3.24 - Heap-Based Buffer Overflow via Integer Overflow in Name Length Field
CVSS 9.8
CVE-2022-24724 HIGH
cmark-gfm <0.29.0.gfm.3-0.28.3.gfm.21 - Memory Corruption
CVSS 8.8
CVE-2022-25062 HIGH
TP-LINK TL-WR840N(ES)_V6.20_180709 - Denial of Service via Integer Overflow in dm_checkString
CVSS 7.5
CVE-2022-0546 HIGH
Blender <3.x-2.93.8 - Memory Corruption
CVSS 7.8
Details
Vulnerabilities 3,200
Exploit Likelihood Medium