CWE-682
139 CVEs • Abstraction: Pillar • Likelihood of Exploit: High
Incorrect Calculation
The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.
CVEs (139)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian Libexpat ProjectNetapp+2 more8Active Iq Unified Manager Debian LinuxHci Baseboard Management Controller+5 moreJun 17, 2026 Jan 1, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). |
2Fedoraproject Toktok2Fedora ToxcoreJun 17, 2026 Dec 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows...Show more |
TensorFlow is an open source platform for machine learning. In affected versions the implementation of `SplitV` can trigger a segfault is an attacker supplies negative arguments. This occurs whenever `size_splits` contai...Show more |
Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions external functions did not properly validate the bounds of decimal arguments. The can lead to logic errors. This issue has been resolved in ve...Show more |
Datalust Seq before 2021.2.6259 allows users (with view filters applied to their accounts) to see query results not constrained by their view filter. This information exposure, caused by an internal cache key collision,...Show more |
In Enbra EWM in Version 1.7.29 together with several tested wireless M-Bus Sensors the events backflow and "no flow" are not reconized or misinterpreted. This may lead to wrong values and missing events. |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Jun 24, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32 platforms. Other platforms are unaffected.*. This vulnerabil...Show more |
2Linux Netapp10Cloud Backup H300e FirmwareH300s Firmware+7 moreJun 17, 2026 May 21, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order t...Show more |
1Siemens 11Scalance Xm 400 Firmware Scalance Xm408 4c FirmwareScalance Xm408 4c L3 Firmware+8 moreJun 17, 2026 May 12, 2021 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device on the SCALANCE...Show more |
4Debian FedoraprojectGolang+1 more5Cloud Insights Telegraf Agent Debian LinuxFedora+2 moreJun 17, 2026 Jan 26, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field. |
2Coturn Project Fedoraproject2Coturn FedoraJun 17, 2026 Jan 13, 2021 N/A· v4 7.2 HIGH· v3 6.4 MEDIUM· v2 Coturn is free open source implementation of TURN and STUN Server. Coturn before version 4.5.2 by default does not allow peers to connect and relay packets to loopback addresses in the range of `127.x.x.x`. However, it w...Show more |
1Stableyieldcredit Project 1Stableyieldcredit Jun 17, 2026 Jan 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should. |
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions...Show more |
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. This is a Consensus vulnerability in Geth before version 1.9.17 which can be used to cause a chain-split where vulnerable nodes reje...Show more |
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. An ethash mining DAG generation flaw in Geth before version 1.9.24 could cause miners to erroneously calculate PoW in an upcoming ep...Show more |
ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation. A guest can crash the QEMU process. |
3Debian FedoraprojectWireshark3Debian Linux FedoraWiresharkJun 17, 2026 Nov 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement. |
4Fedoraproject OpensuseOracle+1 more4Enterprise Manager Ops Center FedoraLeap+1 moreJun 17, 2026 Jun 18, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by t...Show more |
Airbrush FW's scratch memory allocator is susceptible to numeric overflow. When the overflow occurs, the next allocation could potentially return a pointer within the previous allocation's memory, which could lead to imp...Show more |
2Google Huawei22Android Honor 8a FirmwareHonor 8x Firmware+19 moreJun 17, 2026 Feb 13, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privi...Show more |