CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,200 vulnerabilities with CWE-190
CVE-2021-0901 MEDIUM
Android - Local Privilege Escalation via Integer Overflow in apusys
CVSS 6.7
CVE-2021-0677 MEDIUM
Android - Local Information Disclosure via Integer Overflow in CCU Driver
CVSS 4.4
CVE-2021-1047 MEDIUM
Android - Local Information Disclosure via Integer Overflow in valid_ipc_dram_addr
CVSS 4.4
CVE-2021-0968 HIGH
Android - Remote Code Execution via Integer Overflow in osi_malloc and osi_calloc
CVSS 8.8
CVE-2021-0919 MEDIUM
Android 9-11 - Denial of Service via Integer Overflow in IServiceManager getService
CVSS 5.0
CVE-2021-26109 HIGH
FortiOS < 7.0.1 - Unauthenticated Integer Overflow in SSLVPN Memory Allocator
CVSS 8.1
CVE-2021-42688 HIGH
Accops HyWorks Windows Client < 3.2.8.200 - Integer Overflow via IOCTL Handler 0x22005B
CVSS 8.8
CVE-2021-42686 HIGH
Accops HyWorks Windows Client < 3.2.8.200 - Integer Overflow via IOCTL Handler 0x22001B
CVSS 8.8
CVE-2021-42685 HIGH
Accops HyWorks DVM Tools < 3.3.1.105 - Integer Overflow via IOCTL Handler 0x22005B
CVSS 8.8
CVE-2021-42682 HIGH
Accops HyWorks DVM Tools < 3.3.1.105 - Integer Overflow via IOCTL Handler 0x22001B
CVSS 8.8
CVE-2021-43638 HIGH
Amazon WorkSpaces <v1.0.1.1537 - RCE
CVSS 8.8
CVE-2021-43006 HIGH
AmZetta zPortal DVM Tools <= 3.3.148.148 - RCE
CVSS 8.8
CVE-2021-43003 HIGH
Amzetta zPortal Windows zClient <= v3.2.8180.148 - Code Injection
CVSS 8.8
CVE-2021-42996 HIGH
Donglify 1.0.12309-1.7.14110 - Integer Overflow in IOCTL Handler 0x22001B
CVSS 8.8
CVE-2021-42993 HIGH
FlexiHub For Windows <5.3.14268 - RCE
CVSS 8.8
CVE-2021-42987 HIGH
Eltima USB Network Gate <9.2.2420 - RCE
CVSS 8.8
CVE-2021-42986 HIGH
NoMachine Enterprise Client <7.7.4 - RCE
CVSS 8.8
CVE-2021-42979 HIGH
NoMachine Cloud Server <7.7.4 - RCE
CVSS 8.8
CVE-2021-42977 HIGH
NoMachine Enterprise Desktop <7.7.4 - RCE
CVSS 8.8
CVE-2021-42973 HIGH
NoMachine Server 4.0.346-7.7.4 - Integer Overflow in IOCTL Handler 0x22001B
CVSS 8.8
CVE-2021-37095 CRITICAL
HarmonyOS < 2.0 - Integer Overflow or Wraparound
CVSS 9.8
CVE-2021-37065 CRITICAL
HarmonyOS < 2.0 - Integer Overflow or Wraparound
CVSS 9.1
CVE-2021-43784 MEDIUM
runc < 1.0.3 - Namespace Bypass via Netlink Integer Overflow
CVSS 6.0
CVE-2021-26615 HIGH
ARK library - Remote Code Execution via Integer Overflow in Ark_NormalizeAndDupPAthNameW
CVSS 7.8
CVE-2021-0623 MEDIUM
Android - Local Information Disclosure via Integer Overflow in ASF Extractor
CVSS 5.5
Details
Vulnerabilities 3,200
Exploit Likelihood Medium