CWE-190
3,299 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CVEs (3,299)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Linux OpensuseSuse5Linux Enterprise Desktop Linux Enterprise ServerLinux Enterprise Software Development Kit+2 moreApr 29, 2026 Jan 7, 2011 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2...Show more |
4Fedoraproject LinuxOpensuse+1 more7Fedora Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Jan 3, 2011 N/A· v4 N/A· v3 4.7 MEDIUM· v2 Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device. |
4Fedoraproject LinuxOpensuse+1 more7Fedora Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 10, 2010 N/A· v4 N/A· v3 6.2 MEDIUM· v2 Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified...Show more |
3Google RedhatWebmproject5Chrome Enterprise Linux DesktopEnterprise Linux Server+2 moreApr 29, 2026 Nov 6, 2010 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames...Show more |
Multiple integer overflows in Google Chrome before 7.0.517.44 on Linux allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font. |
1Microsoft 6Windows 2003 Server Windows 7Windows Server 2003+3 moreApr 29, 2026 Oct 13, 2010 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote atta...Show more |
The SPDY protocol implementation in Google Chrome before 6.0.472.62 does not properly manage buffers, which might allow remote attackers to execute arbitrary code via unspecified vectors. |
6Canonical DebianFedoraproject+3 more9Debian Linux FedoraLinux Enterprise Desktop+6 moreApr 29, 2026 Oct 4, 2010 N/A· v4 N/A· v3 4.7 MEDIUM· v2 Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have...Show more |
3Canonical LinuxSuse4Linux Enterprise Desktop Linux Enterprise ServerLinux Kernel+1 moreApr 29, 2026 Sep 29, 2010 N/A· v4 N/A· v3 7.2 HIGH· v2 Integer overflow in the ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.33.7 on 32-bit platforms allows local users to cause a denial of service or possibly have unspecified other impact v...Show more |
5Canonical DebianLinux+2 more8Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+5 moreApr 29, 2026 Sep 21, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of t...Show more |
5Debian FedoraprojectLinux+2 more8Debian Linux FedoraLinux Enterprise Desktop+5 moreApr 29, 2026 Sep 8, 2010 N/A· v4 N/A· v3 7.2 HIGH· v2 Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attacke...Show more |
The WebSockets implementation in Google Chrome before 6.0.472.53 does not properly handle integer values, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown v...Show more |
4Apple CanonicalDebian+1 more4Debian Linux FreetypeMac Os X+1 moreApr 29, 2026 Aug 19, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted fon...Show more |
3Mozilla OpensuseSuse7Firefox Linux Enterprise DesktopLinux Enterprise Server+4 moreApr 29, 2026 Jul 30, 2010 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a la...Show more |
5Canonical FedoraprojectOpensuse+2 more5Fedora Linux Enterprise ServerOpensuse+2 moreApr 29, 2026 May 27, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a...Show more |
Integer overflow in rgbimgmodule.c in the rgbimg module in Python 2.5 allows remote attackers to have an unspecified impact via a large image that triggers a buffer overflow. NOTE: this vulnerability exists because of a...Show more |
Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via a crafted .dir (aka Director) file. |
Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir (aka Director) file tha...Show more |
3Opensuse PhpSuse3Linux Enterprise OpensusePhpApr 29, 2026 May 7, 2010 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative ch...Show more |
Multiple integer overflows in Google Chrome before 4.1.249.1036 allow remote attackers to have an unspecified impact via vectors involving WebKit JavaScript objects. |