CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,200 vulnerabilities with CWE-190
CVE-2021-20268 HIGH
Linux Kernel < 5.10.10 - Out-of-Bounds Access in eBPF Verifier via dev_map_init_map or sock_map_alloc
CVSS 7.8
CVE-2021-3420 CRITICAL
newlib < 4.0.0 - Heap-Based Buffer Overflow via Integer Overflow in Memory Allocation Functions
CVSS 9.8
CVE-2021-21309 MEDIUM
Redis 4.0-5.0.10 (32-bit) - Remote Code Execution via Integer Overflow in Bulk Input Handling
CVSS 5.4
CVE-2021-20203 LOW
QEMU < 5.2.0 - Denial of Service via vmxnet3 NIC Parameter Integer Overflow
CVSS 3.2
CVE-2021-3410 HIGH
libcaca v0.99.beta19 - Buffer Overflow in caca_resize Function
CVSS 7.8
CVE-2021-23840 HIGH
OpenSSL 1.0.2-1.0.2x and 1.1.1-1.1.1i - Integer Overflow in EVP_CipherUpdate
CVSS 7.5
CVE-2021-21036 HIGH
Acrobat Reader DC < 20.013.20074 and Acrobat Reader 17.0-17.011.30188 - Unauthenticated Integer Overflow
CVSS 7.8
CVE-2021-26825 HIGH
Godot Engine < 3.2 - Integer Overflow in TGA Image Loader
CVSS 7.8
CVE-2021-0355 MEDIUM
Android 11 - Integer Overflow to Out-of-Bounds Write in kisd
CVSS 6.7
CVE-2021-0354 MEDIUM
Android 8.1-11 - Integer Overflow to Out-of-Bounds Write in ged
CVSS 6.7
CVE-2021-0312 MEDIUM
Android 8.0-11 - Integer Overflow to Out-of-Bounds Write in WAVExtractor
CVSS 6.5
CVE-2021-1059 HIGH
NVIDIA vGPU <8.6-11.3 - Memory Corruption
CVSS 7.8
CVE-2020-21699 HIGH
Tengine 2.2.2 - Integer Overflow in Range Filter Module
CVSS 7.5
CVE-2020-19909 LOW
curl 7.65.2 - Integer Overflow via Large Retry Delay Value
CVSS 3.3
CVE-2020-20335 HIGH
kilo < 2020-07-02 - Denial of Service via editorUpdateRow Buffer Overflow
CVSS 7.5
CVE-2020-6099 HIGH
Graphisoft BIMx Desktop Viewer <2019.2.2328 - RCE
CVSS 7.8
CVE-2020-11263 HIGH
Qualcomm AR8035 and related firmware - Integer Overflow in Address Alignment Check
CVSS 7.3
CVE-2020-7881 HIGH
AfreecaTV - Stack-Based Buffer Overflow via FanTicket Field
CVSS 7.5
CVE-2020-18684 CRITICAL
Floodlight < 1.2 - Integer Overflow via Priority or Port Number
CVSS 9.8
CVE-2020-20898 HIGH
FFmpeg 4.2.1 - Integer Overflow in filter16_prewitt Function
CVSS 8.8
CVE-2020-19497 HIGH
matio 1.5.17 - Integer Overflow in Mat_VarReadNextInfo5
CVSS 8.8
CVE-2020-19490 MEDIUM
tinyexr 0.9.5 - Integer Overflow in DecodePixelData
CVSS 5.5
CVE-2020-22875 CRITICAL
jsish < 3.0.6 - Remote Code Execution via Integer Overflow in Jsi_ObjSetLength
CVSS 9.8
CVE-2020-22874 CRITICAL
jsish <3.0.8 - Remote Code Execution
CVSS 9.8
CVE-2020-7872 HIGH
DaviewIndy <= 8.98.7 - Integer Overflow leading to Remote Code Execution
CVSS 7.8
Details
Vulnerabilities 3,200
Exploit Likelihood Medium