CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,200 vulnerabilities with CWE-190
CVE-2021-32687 HIGH
Redis <6.2.6/<6.0.16/<5.0.14 - Heap Corruption via set-max-intset-entries
CVSS 7.5
CVE-2021-32628 HIGH
Redis 5.0.0-5.0.13 - Remote Code Execution via Ziplist Integer Overflow
CVSS 7.5
CVE-2021-32627 HIGH
Redis 5.0.0-5.0.13 - Remote Code Execution via Integer Overflow in Stream Elements
CVSS 7.5
CVE-2021-21704 MEDIUM
PHP 7.3.0-7.3.28 - Denial of Service via Firebird PDO Driver Response Parsing
CVSS 5.0
CVE-2021-41864 HIGH
Linux Kernel < 5.14.12 - Integer Overflow to Out-of-Bounds Write in eBPF Stackmap
CVSS 7.8
CVE-2021-0610 HIGH
In Memory Management Driver - Memory Corruption
CVSS 7.8
CVE-2021-38094 HIGH
FFmpeg 4.2.1 - Integer Overflow in filter_sobel Function
CVSS 8.8
CVE-2021-38093 HIGH
FFmpeg 4.2.1 - Integer Overflow in filter_robert Function
CVSS 8.8
CVE-2021-38092 HIGH
FFmpeg 4.2.1 - Integer Overflow in filter_prewitt Function
CVSS 8.8
CVE-2021-38091 HIGH
FFmpeg 4.2.1 - Integer Overflow in filter16_sobel Function
CVSS 8.8
CVE-2021-38090 HIGH
FFmpeg 4.2.1 - Integer Overflow in filter16_roberts Function
CVSS 8.8
CVE-2021-30260 HIGH
Qualcomm APQ8009 and other Snapdragon Firmware - Integer Overflow to Buffer Overflow via Extscan Hostlist Configuration
CVSS 8.4
CVE-2021-40346 HIGH
HAProxy <2.6 - HTTP Request Smuggling
CVSS 7.5
CVE-2021-30663 HIGH KEV
Apple OSes and Safari - Code Execution via Malicious Web Content
CVSS 8.8
CVE-2021-1878 MEDIUM
macOS 10.14-10.14.4 and 11.0-11.2 - Information Disclosure via Integer Overflow
CVSS 6.5
CVE-2021-30760 HIGH
Apple OSes - Code Execution via Malicious Font File
CVSS 7.8
CVE-2021-39254 HIGH
NTFS-3G < 2021.8.22 - Heap-Based Buffer Overflow via Crafted NTFS Image
CVSS 7.8
CVE-2021-30354 HIGH
Amazon Kindle <5.13.4 - Code Injection
CVSS 8.6
CVE-2021-36058 MEDIUM
XMP Toolkit SDK < 2020.1 - Denial of Service via Crafted File
CVSS 5.5
CVE-2021-22684 HIGH
Tizen RT RTOS <3.0.GBB - Memory Corruption
CVSS 7.5
CVE-2021-21850 HIGH
GPAC 1.0.1 - Integer Overflow via MPEG-4 'trun' Atom Handling
CVSS 8.8
CVE-2021-30952 HIGH KEV
Apple OSes and Safari - Code Execution via Malicious Web Content
CVSS 7.8
CVE-2021-30907 HIGH
iPadOS/iOS <14.8.1, macOS <10.15.7/>=11.0 <11.6.1, tvOS <15.1, watchOS <8.1 - Privilege Escalation via Integer Overflow
CVSS 7.8
CVE-2021-30860 HIGH KEV
Apple iOS/iPadOS/macOS - Integer Overflow in PDF Processing
CVSS 7.8
CVE-2021-38714 HIGH
plib < 1.8.5 - Integer Overflow in ssgLoadTGA()
CVSS 8.8
Details
Vulnerabilities 3,200
Exploit Likelihood Medium