CWE-190
3,299 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CVEs (3,299)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple integer overflows in potrace 1.11 allow remote attackers to cause a denial of service (crash) via large dimensions in a BMP image, which triggers a buffer overflow. |
3Canonical GoogleRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 moreMay 6, 2026 Mar 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service...Show more |
Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against h...Show more |
Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows remote attackers to cause a denial of service (server crash) via a craft...Show more |
3Debian OracleX.org3Debian Linux SolarisX ServerMay 6, 2026 Dec 10, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (c...Show more |
3Adobe OpensuseSuse7Air Desktop Runtime Air SdkEvergreen+4 moreMay 6, 2026 Oct 15, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe A...Show more |
4Canonical LinuxRedhat+1 more9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX access, related to (...Show more |
3Canonical LinuxSuse3Linux Enterprise Server Linux KernelUbuntu LinuxMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local users to cause a denial o...Show more |
4Canonical LinuxOpensuse+1 more5Linux Enterprise Real Time Extension Linux Enterprise ServerLinux Kernel+2 moreMay 6, 2026 Jul 3, 2014 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service...Show more |
4Canonical DebianLinux+1 more4Debian Linux LinuxLinux Kernel+1 moreMay 6, 2026 May 11, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain length value is suffic...Show more |
Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a crafted image to the (1) png_set_sPLT or (2) png_set_text_2 function, which triggers a heap-based b...Show more |
Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a crafted image,...Show more |
Integer overflow in api.cc in Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, allows remote attackers to cause a denial of service or possibly have unspecif...Show more |
4Armin Burgmeier OpensuseOpensuse Project+1 more4Net6 OpensuseOpensuse+1 moreApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occu...Show more |
Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and po...Show more |
6Canonical FedoraprojectMozilla+3 more9Fedora FirefoxLinux Enterprise Desktop+6 moreApr 29, 2026 Dec 11, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-of-bounds array acces...Show more |
1Microsoft 10Windows 7 Windows 8Windows 8.1+7 moreApr 29, 2026 Dec 11, 2013 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2...Show more |
1Microsoft 10Windows 7 Windows 8Windows 8.1+7 moreApr 29, 2026 Nov 13, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows...Show more |
Integer overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denial of service (application crash) via a (1) large or (2) small value in the subview attribute of a vi...Show more |
2Debian Systemd Project2Debian Linux SystemdApr 29, 2026 Oct 28, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, w...Show more |