CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,206 vulnerabilities with CWE-190
CVE-2019-9210 HIGH
AdvanceCOMP 2.1 - Integer Overflow via Invalid PNG Size Handling
CVSS 7.8
CVE-2019-9112 MEDIUM
xiaomi_perseus-p-oss < 2018-11-26 - Integer Overflow in msm GPU Driver
CVSS 5.5
CVE-2019-9111 MEDIUM
xiaomi_perseus-p-oss < 2018-11-26 - Integer Overflow in msm GPU Driver sde_evtlog_filter_write
CVSS 5.5
CVE-2019-8355 MEDIUM
Sound Exchange - Integer Overflow
CVSS 5.5
CVE-2019-8354 MEDIUM
Sound Exchange - Integer Overflow
CVSS 5.0
CVE-2019-7733 HIGH
Live555 0.95 - Buffer Overflow via Large Content-Length HTTP Header
CVSS 7.5
CVE-2019-6983 MEDIUM
Foxit 3D Plugin Beta <9.4.0.16807 - Memory Corruption
CVSS 6.5
CVE-2019-6250 HIGH
libzmq 4.2.0-4.2.4 and 4.3.0 - Authenticated Integer Overflow to Remote Code Execution in v2_decoder.cpp
CVSS 8.8
CVE-2018-9404 MEDIUM
Android - Integer Overflow to Out-of-Bounds Write in ril.cpp oemCallback
CVSS 6.7
CVE-2018-9352 MEDIUM
Android - Remote Denial of Service via Integer Overflow in ihevcd_allocate_dynamic_bufs
CVSS 6.5
CVE-2018-9482 MEDIUM
Android - Local Information Disclosure via Integer Overflow in Bluetooth Service
CVSS 6.5
CVE-2018-9481 MEDIUM
Android - Remote Information Disclosure via Integer Overflow in bta_hd_set_report_act
CVSS 6.5
CVE-2018-9472 HIGH
Android - Remote Code Execution via Integer Overflow in xmlMemStrdupLoc
CVSS 8.8
CVE-2018-9366 HIGH
Android - Integer Overflow to Out-of-Bounds Write in ImsaClient.cpp and VideoTelephony.c
CVSS 7.8
CVE-2018-9348 MEDIUM
Android - Remote Denial of Service via Integer Overflow in SMF_ParseMetaEvent
CVSS 6.5
CVE-2018-10195 HIGH
lrzsz <0.12.21~rc - Info Disclosure
CVSS 7.1
CVE-2018-12371 HIGH
Firefox < 61 and Firefox ESR < 60.1 - Use-After-Free via Skia Edge Builder Memory Allocation
CVSS 8.8
CVE-2018-21054 CRITICAL
Android M(6.0) N(7.x) O(8.x) - Integer Underflow and Buffer Overflow in eCryptFS
CVSS 9.8
CVE-2018-21089 CRITICAL
Samsung Android N(7.x) Mediatek MT6755/MT6757 - Arbitrary Code Execution via Bootloader Download Offset Control
CVSS 9.8
CVE-2018-16301 HIGH
tcpdump < 4.99.0 - Buffer Overflow via -F Command-Line Argument
CVSS 7.8
CVE-2018-21009 HIGH
Poppler < 0.76.0 - Integer Overflow in Parser Stream Creation
CVSS 8.8
CVE-2018-16070 HIGH
Google Chrome < 69.0.3497.81 - Remote Code Execution via Integer Overflow in Skia
CVSS 8.8
CVE-2018-20847 HIGH
OpenJPEG < 2.3.0 - Integer Overflow in opj_get_encoding_parameters
CVSS 8.8
CVE-2018-13887 CRITICAL
Qualcomm MDM9150 and related firmware - Integer Overflow in GNSS XTRA3 Header Parsing
CVSS 9.8
CVE-2018-13886 CRITICAL
Qualcomm MDM9150 and related firmware - Integer Overflow and Buffer Overflow via GNSS XTRA3 OTA Field
CVSS 9.8
Details
Vulnerabilities 3,206
Exploit Likelihood Medium