CWE-190
3,306 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CVEs (3,306)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error can occur when handling the client address length field in an NFSv4 request. Unprivileged remote users with access to the NFS server c...Show more |
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request. Unprivileged remote users with access...Show more |
4Canonical DebianFreerdp+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreJun 17, 2026 Nov 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption and probably even a remote code execution. |
VMware Workstation (15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (11.x before 11.0.2 and 10.x before 10.1.5) contain an integer overflow vulnerability in the virtual network devices. This issue may allow a guest...Show more |
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing a fast Initial link setup (FILS) connection request, integer overflow may lead to a buffer overf...Show more |
3Debian GoogleRedhat5Chrome Debian LinuxLinux Desktop+2 moreJun 17, 2026 Nov 14, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. |
3Debian GoogleRedhat5Chrome Debian LinuxLinux Desktop+2 moreJun 17, 2026 Nov 14, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An integer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. |
4Debian GoogleMi+1 more6Chrome Debian LinuxEnterprise Linux Desktop+3 moreJun 17, 2026 Nov 14, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a c...Show more |
2Debian Uriparser Project2Debian Linux UriparserNov 21, 2024 Nov 12, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication. |
4Canonical DebianExiv2+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Nov 8, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD im...Show more |
4Canonical DebianGoogle+1 more4Android Debian LinuxLinux Kernel+1 moreJun 17, 2026 Nov 6, 2018 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: A...Show more |
1Icu Project 1International Components For Unicode Nov 21, 2024 Nov 4, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificString() in i18n/number_decimalquantity.cpp. |
2Debian Powerdns2Authoritative Debian LinuxNov 21, 2024 Nov 1, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash the server by inserting a specially crafted record in a zone under their control th...Show more |
3Canonical DebianLibexif Project3Debian Linux LibexifUbuntu LinuxNov 21, 2024 Oct 31, 2018 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metada...Show more |
3Canonical DebianHaxx3Curl Debian LinuxUbuntu LinuxNov 21, 2024 Oct 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service. |
When the buffer length passed is very large, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon Mobile in version SD 845 |
1Qualcomm 25Ipq8074 Firmware Mdm9206 FirmwareMdm9607 Firmware+22 moreNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Integer overflow may happen in WLAN when calculating an internal structure size due to lack of validation of the input length in Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9650, SD 210/SD...Show more |
1Qualcomm 24Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+21 moreNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Integer overflow may happen when calculating an internal structure size due to lack of validation of the input length in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 4...Show more |
1Data Tools Project 1Data Tools Nov 21, 2024 Oct 29, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 data-tools through 2017-07-26 has an Integer Overflow leading to an incorrect end value for the write_wchars function. |
1Qualcomm 4Sd 835 Firmware Sd 845 FirmwareSd 850 Firmware+1 moreNov 21, 2024 Oct 26, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A possible integer overflow may happen in WLAN during memory allocation in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660 |