CWE-190

Medium likelihood

Integer Overflow or Wraparound

Parent: CWE-682 - Incorrect Calculation

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

3,206 vulnerabilities with CWE-190
CVE-2018-6090 HIGH
Google Chrome < 66.0.3359.117 - Remote Code Execution via Integer Overflow in Skia
CVSS 8.8
CVE-2018-17158 HIGH
FreeBSD <11.2-STABLE(r340854) and 11.2-RELEASE-p5 - Memory Corruption
CVSS 7.5
CVE-2018-17157 CRITICAL
FreeBSD <11.2-STABLE(r340854) and 11.2-RELEASE-p5 - Memory Corruption
CVSS 9.8
CVE-2018-8787 CRITICAL
FreeRDP <2.0.0-rc4 - Memory Corruption
CVSS 9.8
CVE-2018-6983 HIGH
VMware Workstation 14.0.0-14.1.5 and Fusion 10.0.0-10.1.5 - Integer Overflow in Virtual Network Devices
CVSS 8.8
CVE-2018-11260 HIGH
Android - Buffer Overflow via FILS Connection Request with Zero Key Length
CVSS 7.8
CVE-2018-6072 HIGH
Google Chrome <65.0.3325.146 - Use After Free
CVSS 8.8
CVE-2018-6071 HIGH
Google Chrome <65.0.3325.146 - Memory Corruption
CVSS 8.8
CVE-2018-6065 HIGH KEV
Google Chrome <65.0.3325.146 - Heap Corruption
CVSS 8.8
CVE-2018-19199 CRITICAL
uriparser < 0.9.0 - Integer Overflow in UriQuery.c
CVSS 9.8
CVE-2018-19107 MEDIUM
Exiv2 0.26 - Denial of Service via Integer Overflow in PSD Image Parser
CVSS 6.5
CVE-2018-9363 HIGH
Android - Integer Overflow in Bluetooth HIDP Report Processing
CVSS 8.4
CVE-2018-18928 CRITICAL
International Components for Unicode (ICU) for C/C++ 63.1 - Integer Overflow in DecimalQuantity::toScientificString()
CVSS 9.8
CVE-2018-16839 MEDIUM
curl 7.33.0-7.61.1 - Denial of Service via SASL Authentication Buffer Overrun
CVSS 4.3
CVE-2018-11879 HIGH
Snapdragon Mobile <SD 845 - Buffer Overflow
CVSS 7.8
CVE-2018-11866 HIGH
Snapdragon Mobile/Snapdragon Wear - Integer Overflow
CVSS 7.8
CVE-2018-11865 HIGH
Qualcomm Snapdragon Mobile and Wear - Integer Overflow
CVSS 7.8
CVE-2018-18749 MEDIUM
data_tools < 2017-07-26 - Integer Overflow in write_wchars
CVSS 5.5
CVE-2018-11822 HIGH
Snapdragon Mobile <SD 850 - Buffer Overflow
CVSS 7.8
CVE-2018-11821 HIGH
Snapdragon Mobile/Snapdragon Wear - Memory Corruption
CVSS 7.8
CVE-2018-18650 MEDIUM
Xpdf 4.00 - Denial of Service via Crafted /Size Value in PDF File
CVSS 5.5
CVE-2018-18438 MEDIUM
Qemu - Integer Overflow in IOReadHandler
CVSS 5.5
CVE-2018-18483 HIGH
GNU Binutils - Integer Overflow in get_count Function
CVSS 7.8
CVE-2018-12362 HIGH
Thunderbird <60 - Buffer Overflow
CVSS 8.8
CVE-2018-12361 HIGH
Thunderbird <60, Firefox ESR <60.1, Firefox <61 - Buffer Overflow
CVSS 8.8
Details
Vulnerabilities 3,206
Exploit Likelihood Medium