CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,200 vulnerabilities with CWE-190
CVE-2021-31870 CRITICAL
klibc < 2.0.9 - Integer Overflow to Heap Buffer Overflow in calloc()
CVSS 9.8
CVE-2021-31426 HIGH
Parallels Desktop 16.1.2-49151 - Local Privilege Escalation via Integer Overflow in Parallels Tools
CVSS 8.8
CVE-2021-31425 HIGH
Parallels Desktop 16.1.2-49151 - Local Privilege Escalation via Integer Overflow in Parallels Tools
CVSS 8.8
CVE-2021-21223 CRITICAL
Google Chrome <90.0.4430.85 - Sandbox Escape
CVSS 9.6
CVE-2021-31572 CRITICAL
Amazon FreeRTOS < 10.4.3 - Integer Overflow in Stream Buffer
CVSS 9.8
CVE-2021-31571 CRITICAL
Amazon FreeRTOS < 10.4.3 - Integer Overflow in Queue Creation
CVSS 9.8
CVE-2021-30022 MEDIUM
GPAC 0.5.2-1.0.1 - Integer Overflow in av_parsers.c
CVSS 5.5
CVE-2021-30014 MEDIUM
GPAC 0.9.0-1.0.1 - Integer Overflow in HEVC Slice Segment Parser
CVSS 5.5
CVE-2021-29279 HIGH
GPAC 1.0.1 - Integer Overflow in gf_props_assign_value
CVSS 7.8
CVE-2021-27259 HIGH
Parallels Desktop 16.0.1-48919 - Privilege Escalation
CVSS 7.8
CVE-2021-29338 MEDIUM
OpenJPEG 2.4.0 - Denial of Service via Integer Overflow in -ImgDir Option
CVSS 5.5
CVE-2021-0471 MEDIUM
Android - Local Information Disclosure via Integer Overflow in CryptoPlugin.cpp
CVSS 5.5
CVE-2021-0436 MEDIUM
Android -8.1,9,10,11 - Info Disclosure
CVSS 5.5
CVE-2021-28879 CRITICAL
Rust < 1.52.0 - Integer Overflow in Zip Implementation
CVSS 9.8
CVE-2021-20308 CRITICAL
htmldoc < 1.9.11 - Integer Overflow
CVSS 9.8
CVE-2021-3477 MEDIUM
OpenEXR < 3.0.0-beta - Integer Overflow via Deep Tile Sample Size Calculation
CVSS 5.5
CVE-2021-3476 MEDIUM
OpenEXR < 3.0.0-beta - Denial of Service via B44 Uncompression Shift Overflow
CVSS 5.3
CVE-2021-3475 MEDIUM
OpenEXR < 3.0.0-beta - Integer Overflow
CVSS 5.3
CVE-2021-3474 MEDIUM
OpenEXR < 3.0.0-beta - Denial of Service via FastHufDecoder Shift Overflow
CVSS 5.3
CVE-2021-27243 HIGH
Parallels Desktop 16.0.1-48919 - Privilege Escalation
CVSS 8.8
CVE-2021-21783 CRITICAL
Genivia gSOAP 2.8.107 - Remote Code Execution via WS-Addressing Plugin
CVSS 9.8
CVE-2021-0460 MEDIUM
Android - Integer Overflow Leading to Out-of-Bounds Read in FingerTipS Touch Screen Driver
CVSS 4.4
CVE-2021-0458 MEDIUM
Android - Integer Overflow to Out-of-Bounds Read in FingerTipS Touch Screen Driver
CVSS 4.4
CVE-2021-24025 CRITICAL
HHVM < 4.56.3, 4.57.0-4.80.1, 4.81.0-4.93.1, 4.94.0-4.98.0 Heap Overflow via preg_quote
CVSS 9.8
CVE-2021-0393 HIGH
Android - Remote Code Execution via Integer Overflow in Scanner::LiteralBuffer::NewCapacity
CVSS 7.8
Details
Vulnerabilities 3,200
Exploit Likelihood Medium