CWE-190
3,306 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CVEs (3,306)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Libsdl Opensuse3Backports Sle LeapSdl2 ImageJun 17, 2026 Jul 31, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer...Show more |
A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parameter passed to an ioctl was incorrectly validated and used in size calculations fo...Show more |
4Canonical GnuNetapp+1 more5Binutils Hci Management NodeLeap+2 moreJun 17, 2026 Jul 30, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrate...Show more |
2Linuxfoundation Nats2Nats Server Nats ServerJun 17, 2026 Jul 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authenticated. |
An Integer overflow in the getElfSections function in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed execu...Show more |
An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case. |
An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case. |
In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c does not validate the sect and head fields, as demonstrated by an integer overflow and out-of-bounds read. It can be triggered by an unprivileged l...Show more |
1Qualcomm 24Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+21 moreJun 17, 2026 Jul 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 While storing calibrated data from firmware in cache, An integer overflow may occur since data length received may exceed real data length. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Con...Show more |
3Canonical GnuOpensuse3Binutils LeapUbuntu LinuxJun 17, 2026 Jul 24, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-ba...Show more |
In SweetScape 010 Editor 9.0.1, an integer overflow during the initialization of variables could allow an attacker to cause a denial of service. |
4Debian FedoraprojectFreedesktop+1 more7Debian Linux Enterprise LinuxEnterprise Linux Eus+4 moreJun 17, 2026 Jul 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with...Show more |
1Linuxfoundation 1Open Network Operating System Jun 17, 2026 Jul 18, 2019 N/A· v4 4.9 MEDIUM· v3 5.5 MEDIUM· v2 The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow(...Show more |
3Debian FedoraprojectSleuthkit3Debian Linux FedoraThe Sleuth KitJun 17, 2026 Jul 18, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers crash in tsk/fs/hfs_dent.c:237. The component is: Overflow in fls tool used on HFS image. Bug is in ts...Show more |
5Debian F5Fedoraproject+2 more7Cloud Backup Debian LinuxE Series Santricity Os Controller+4 moreJun 17, 2026 Jul 16, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attack...Show more |
2Linaro Trustedfirmware2Op Tee Op TeeJun 17, 2026 Jul 15, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later. |
2Linaro Trustedfirmware2Op Tee Op TeeJun 17, 2026 Jul 15, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Execution of code in TEE core (kernel) context. The component is: optee_os. The fixed version is: 3.4.0 and later. |
2Linaro Trustedfirmware2Op Tee Op TeeJun 17, 2026 Jul 15, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later. |
4Canonical DebianGnome+1 more4Debian Linux EvinceLeap+1 moreJun 17, 2026 Jul 15, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs beca...Show more |
1Sound Exchange Project 1Sound Exchange Jun 17, 2026 Jul 14, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libsox.a in SoX 14.4.2. In sox-fmt.h (startread function), there is an integer overflow on the result of integer addition (wraparound to 0) fed into the lsx_calloc macro that wraps malloc. When...Show more |