Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2026-34333HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-61937HIGHWindows HTTP.sys Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69738HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69707HIGHWindows USB Audio Class driver (usbaudio.sys) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-54115HIGHWindows Message Queuing (MSMQ) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69298HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-45593HIGHWindows SDK Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-34330HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-72995HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-45592HIGHWindows Internet (wininet.dll) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-48486HIGHSignum Node: Integer overflow in SMART_FEES fee distribution allows arbitrary miner reward inflationEPSS 0.3%CVE-2026-59127HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-49800HIGHWindows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62735HIGHWindows HTTP.sys Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69584HIGHWindows USB Video Driver Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-49179HIGHXorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x record extensionEPSS 0.3%CVE-2026-46463MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.3%CVE-2026-53910LOWHeap-based Buffer Overflow in GNU diffutilsEPSS 0.3%CVE-2026-59088MEDIUMGimp: gimp: denial of service via signed integer overflow in fli file processingEPSS 0.3%CVE-2026-18300HIGHGIMP HDR File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 0.3%