CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,200 vulnerabilities with CWE-190
CVE-2020-2742 HIGH
Oracle VM VirtualBox < 5.2.36, < 6.0.16, < 6.1.2 - Authenticated Integer Overflow in Core
CVSS 8.2
CVE-2020-11759 MEDIUM
OpenEXR < 2.4.1 - Integer Overflow via Deep Frame Buffer Handling
CVSS 5.5
CVE-2020-1895 HIGH
Instagram for Android <128.0.0.26.128 - Buffer Overflow
CVSS 7.8
CVE-2020-1634 HIGH
Juniper Junos 12.3X48-D80-12.3X48-D94 - Denial of Service via Multicast Traffic Handling
CVSS 7.5
CVE-2020-6073 HIGH
libmicrodns 0.1.0 - Denial of Service via TXT Record RDATA Parsing
CVSS 7.5
CVE-2020-10938 CRITICAL
GraphicsMagick <1.3.35 - Buffer Overflow
CVSS 9.8
CVE-2020-8874 MEDIUM
Parallels Desktop 15.1.2-47123 - Privilege Escalation
CVSS 6.7
CVE-2020-0086 CRITICAL
Android 10 - Integer Overflow to Arbitrary Code Execution in Parcel.cpp
CVSS 9.8
CVE-2020-10531 HIGH
International Components for Unicode < 66.1 - Heap-Based Buffer Overflow via UnicodeString::doAppend() Integer Overflow
CVSS 8.8
CVE-2020-8844 HIGH
Foxit Reader < 9.7.0.29478 and PhantomPDF < 9.7.0.29455 - Remote Code Execution via JPEG Parsing Integer Overflow
CVSS 7.8
CVE-2020-6381 HIGH
Google Chrome <80.0.3987.87 - Heap Corruption
CVSS 8.8
CVE-2020-3120 MEDIUM
Cisco FXOS, IOS XR, NX-OS - Unauthenticated Denial of Service via Cisco Discovery Protocol
CVSS 6.5
CVE-2020-6059 HIGH
MiniSNMPD 1.4 - Info Disclosure/DoS
CVSS 8.2
CVE-2020-5310 HIGH
Pillow < 6.2.2 - Integer Overflow in TIFF Decoding
CVSS 8.8
CVE-2019-25039 CRITICAL
Unbound < 1.9.5 - Integer Overflow in Respip Size Calculation
CVSS 9.8
CVE-2019-25038 CRITICAL
Unbound < 1.9.5 - Integer Overflow in dnscrypt Size Calculation
CVSS 9.8
CVE-2019-25034 CRITICAL
Unbound < 1.9.5 - Integer Overflow via sldns_str2wire_dname_buf_origin
CVSS 9.8
CVE-2019-25033 CRITICAL
Unbound < 1.9.5 - Integer Overflow in Regional Allocator
CVSS 9.8
CVE-2019-25032 CRITICAL
Unbound < 1.9.5 - Integer Overflow in Regional Allocator
CVSS 9.8
CVE-2019-19004 LOW
autotrace 0.31.1 - Integer Overflow in input-bmp.c
CVSS 3.3
CVE-2019-25005 HIGH
chacha20 < 0.2.3 - Integer Overflow in ChaCha20 Counter
CVSS 7.5
CVE-2019-2392 MEDIUM
MongoDB Server <4.4.1, <4.2.9, <4.0.20, <3.6.20 - DoS
CVSS 6.5
CVE-2019-14562 MEDIUM
EDK II - Integer Overflow in DxeImageVerificationHandler
CVSS 5.5
CVE-2019-16127 CRITICAL
Microchip Advanced Software Framework 4 - Integer Overflow in flash_read, flash_write, and flash_append
CVSS 9.1
CVE-2019-14074 HIGH
Qualcomm Snapdragon - Heap Overflow in Diag Command Handler
CVSS 7.8
Details
Vulnerabilities 3,200
Exploit Likelihood Medium