Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2024-41851HIGHAdobe InDesign (Beta) has an integer overflow vulnerability when parsing SVG fileEPSS 0.3%CVE-2024-47424HIGHAdobe Framemaker | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-62751HIGHWindows Projected File System Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50306HIGHWindows TCP/IP Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-48486HIGHSignum Node: Integer overflow in SMART_FEES fee distribution allows arbitrary miner reward inflationEPSS 0.3%CVE-2026-70581HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-42916HIGHNT OS Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69608HIGHMicrosoft Windows Search Component Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-73002HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-42896HIGHWindows DWM Core Library Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-56182HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-65814HIGHMicrosoft Windows Storage Port Driver Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-54109HIGHWindows Resilient File System (ReFS) Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-61937HIGHWindows HTTP.sys Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-45592HIGHWindows Internet (wininet.dll) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-49800HIGHWindows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-72990HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-68832HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-35415HIGHWindows Storage Spaces Controller Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-84000HIGHMicrosoft Graphics Component Remote Code Execution VulnerabilityEPSS 0.3%