CWE-190
3,531 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CVEs (3,531)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privi...Show more |
7Debian FujitsuMcafee+4 more21Business Intelligence Communications Cloud Native Core PolicyDebian Linux+18 moreJun 17, 2026 Feb 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. I...Show more |
2Autotrace Project Fedoraproject2Autotrace FedoraJun 17, 2026 Feb 11, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image. |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreJun 17, 2026 Feb 11, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Integer Overflow vulnerability. An unauthenticated attacker could leverag...Show more |
2Fedoraproject Genivia2Fedora GsoapJun 17, 2026 Feb 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigge...Show more |
1Softmaker 1Office Textmaker 2021 Jun 17, 2026 Feb 10, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In SoftMaker Software GmbH SoftMaker Office TextMaker 2021 (revision 1014), a specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer t...Show more |
An integer overflow has been found in the the latest version of Issuer. The total issuedCount can be zero if the parameter is overly large. An attacker can obtain the private key of the owner issued with a certain 'amoun...Show more |
An integer overflow issue exists in Godot Engine up to v3.2 that can be triggered when loading specially crafted.TGA image files. The vulnerability exists in ImageLoaderTGA::load_image() function at line: const size_t bu...Show more |
3Cryptography.io FedoraprojectOracle3Communications Cloud Native Core Network Function Cloud Native Environment CryptographyFedoraJun 17, 2026 Feb 7, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class...Show more |
An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. A specially crafted document can cause the document parser perform ar...Show more |
2Oracle Windriver2Communications Eagle VxworksJun 17, 2026 Feb 3, 2021 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by th...Show more |
In kisd, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Prod...Show more |
In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Produ...Show more |
1Qualcomm 369Apq8009 Apq8009wApq8017+366 moreJun 17, 2026 Jan 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sna...Show more |
1Qualcomm 370Apq8009 Apq8009wApq8017+367 moreJun 17, 2026 Jan 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Possible integer overflow can occur when stream info update is called when total number of streams detected are zero while parsing TS clip with invalid data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity...Show more |
1Qualcomm 286Apq8009w Apq8017Apq8037+283 moreJun 17, 2026 Jan 21, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Memory corruption while calculating L2CAP packet length in reassembly logic when remote sends more data than expected in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon I...Show more |
1Qualcomm 491Apq8009 Apq8009wApq8017+488 moreJun 17, 2026 Jan 21, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Integer multiplication overflow resulting in lower buffer size allocation than expected causes memory access out of bounds resulting in possible device instability in Snapdragon Auto, Snapdragon Compute, Snapdragon Conne...Show more |
4Debian FedoraprojectLibsdl+1 more4Debian Linux FedoraSimple Directmedia Layer+1 moreJun 17, 2026 Jan 19, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file. |
In WAVSource::read of WAVExtractor.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interactio...Show more |
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |