CWE-190
3,532 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CVEs (3,532)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 May 11, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and proc...Show more |
An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenticated message received from the device be...Show more |
1Ti 7Cc3100 Software Development Kit Cc3200 Software Development KitSimplelink Cc13x0 Software Development Kit+4 moreJun 17, 2026 May 7, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network may lead to issues such as a denial-of-service condition or code execution on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00....Show more |
1Ti 7Cc3100 Software Development Kit Cc3200 Software Development KitSimplelink Cc13x0 Software Development Kit+4 moreJun 17, 2026 May 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple integer overflow issues exist while processing long domain names, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and pri...Show more |
1Ti 7Cc3100 Software Development Kit Cc3200 Software Development KitSimplelink Cc13x0 Software Development Kit+4 moreJun 17, 2026 May 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30...Show more |
1Ti 7Cc3100 Software Development Kit Cc3200 Software Development KitSimplelink Cc13x0 Software Development Kit+4 moreJun 17, 2026 May 7, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The affected product is vulnerable to integer overflow while parsing malformed over-the-air firmware update files, which may allow an attacker to remotely execute code on SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and p...Show more |
1Qualcomm 414Apq8009w Firmware Apq8017 FirmwareApq8053 Firmware+411 moreJun 17, 2026 May 7, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music |
1Qualcomm 408Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+405 moreJun 17, 2026 May 7, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industria...Show more |
Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by leveraging the mishandling of continuation lines during header-length restriction. |
Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: remote exploitation may be difficult because of resource consumption. |
Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow because get_stdinput allows unbounded reads that are accompanied by unbounded increases in a certain size variable. NOTE: exploitation may be impractical be...Show more |
2Fedoraproject Redislabs2Fedora RedisJun 17, 2026 May 4, 2021 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt the heap and potentia...Show more |
2Fedoraproject Redislabs2Fedora RedisJun 17, 2026 May 4, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer could be exploited using the `STRALGO LCS` comm...Show more |
2Debian Klibc Project2Debian Linux KlibcJun 17, 2026 Apr 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and a subsequent heap buffer overflow. |
2Debian Klibc Project2Debian Linux KlibcJun 17, 2026 Apr 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems may result in a buffer overflow or other security impact. |
2Debian Klibc Project2Debian Linux KlibcJun 17, 2026 Apr 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dereference on 64-bit systems. |
2Debian Klibc Project2Debian Linux KlibcJun 17, 2026 Apr 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer overflow. |
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.2-49151. An attacker must first obtain the ability to execute low-privileged code on the target system...Show more |
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.2-49151. An attacker must first obtain the ability to execute low-privileged code on the target guest s...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot...Show more |