CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,200 vulnerabilities with CWE-190
CVE-2019-19638 CRITICAL
libsixel 1.8.2 - Heap-Based Buffer Overflow via Integer Overflow in load_pnm
CVSS 9.8
CVE-2019-19637 CRITICAL
libsixel 1.8.2 - Integer Overflow in sixel_decode_raw_impl
CVSS 9.8
CVE-2019-19636 CRITICAL
libsixel 1.8.2 - Integer Overflow in sixel_encode_body
CVSS 9.8
CVE-2019-1551 MEDIUM
x64_64 Montgomery squaring procedure - Buffer Overflow
CVSS 5.3
CVE-2019-19590 HIGH
radare2 < 4.0.0 - Use-After-Free via Integer Overflow in r_asm_massemble
CVSS 7.8
CVE-2019-19307 CRITICAL
Cesanta Mongoose 6.16 - Remote Denial of Service via Crafted MQTT Packet
CVSS 9.8
CVE-2019-5855 MEDIUM
Google Chrome < 76.0.3809.87 - Integer Overflow in PDFium via Crafted PDF File
CVSS 6.5
CVE-2019-5854 HIGH
Google Chrome < 76.0.3809.87 - Integer Overflow in PDFium via Crafted PDF File
CVSS 8.8
CVE-2019-18675 HIGH
Linux kernel <5.3.13 - Privilege Escalation
CVSS 7.8
CVE-2019-5087 HIGH
xcftools 1.0.7 - Integer Overflow in flattenIncrementally Function
CVSS 8.8
CVE-2019-5086 HIGH
xcftools 1.0.7 - Integer Overflow in flattenIncrementally Function
CVSS 8.8
CVE-2019-2297 HIGH
Qualcomm APQ/MDM/MSM/QCA/QCN/QCS/SDA/SDM/SDX/SM Firmware - Buffer Overflow via NAN Message Processing
CVSS 7.8
CVE-2019-10627 CRITICAL
Qualcomm IPS < 2019.2 - Integer Overflow to Buffer Overflow in PostScript Image Handling
CVSS 9.8
CVE-2019-19012 CRITICAL
Oniguruma <6.9.4_rc2 - Memory Corruption
CVSS 9.8
CVE-2019-5288 HIGH
P30 <ELLE-AL00B 9.1.0.193(C00E190R2P1 - Code Injection
CVSS 7.8
CVE-2019-5287 HIGH
P30 smart phones < ELLE-AL00B 9.1.0.193(C00E190R2P1 - Code Injection
CVSS 7.8
CVE-2019-18805 CRITICAL
Linux Kernel < 5.0.11 - Denial of Service via Integer Overflow in tcp_ack_update_rtt
CVSS 9.8
CVE-2019-5100 HIGH
LEADTOOLS 20 - Integer Overflow in BMP Header Parsing
CVSS 7.8
CVE-2019-2331 CRITICAL
Qualcomm Snapdragon Auto/Mobile/Compute/IOT/Wearables - Buffer Over...
CVSS 9.8
CVE-2019-2302 CRITICAL
Snapdragon Auto et al. - Buffer Overflow
CVSS 9.8
CVE-2019-5089 HIGH
Investintech Able2Extract Professional 4.0.7 x64 - Memory Corruption
CVSS 7.8
CVE-2019-17211 CRITICAL
Arm Mbed OS 5.14.0 - Integer Overflow in CoAP Message Buffer Calculation
CVSS 9.8
CVE-2019-17498 HIGH
libssh2 < 1.9.0 - Integer Overflow in SSH_MSG_DISCONNECT Bounds Check
CVSS 8.1
CVE-2019-17546 HIGH
libtiff < 4.1.0 - Integer Overflow via Crafted RGBA Image
CVSS 8.8
CVE-2019-17451 MEDIUM
GNU Binutils 2.32 - Integer Overflow in BFD Library via DWARF2 Line Number Parsing
CVSS 6.5
Details
Vulnerabilities 3,200
Exploit Likelihood Medium