Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2025-69261MEDIUMWasmEdge integer wrap in MemoryInstance::getSpan()'s memory size checkEPSS 0.3%CVE-2023-23385HIGHWindows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-33204HIGHsysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplEPSS 0.3%CVE-2026-10758HIGHEsri Lerc has a security vulnerabilityEPSS 0.3%CVE-2026-42046HIGHlibcaca: Heap OOB write in canvas import functions caused by int overflowEPSS 0.3%CVE-2026-58384HIGHGimp: gimp: integer overflow in read_rle_channel()EPSS 0.3%CVE-2025-49180HIGHXorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x resize, rotate and reflect (randr) extensionEPSS 0.3%CVE-2025-48175MEDIUMIn libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer overflows in multiplications involving rgbRowBytes, yRowBytes, uRowByteEPSS 0.3%CVE-2022-47660HIGHGPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is has an integer overflow in isomedia/isom_write.cEPSS 0.3%CVE-2023-23144MEDIUMInteger overflow vulnerability in function Q_DecCoordOnUnitSphere file bifs/unquantize.c in GPAC version 2.2-rev0-gab012bbfb-master.EPSS 0.3%CVE-2025-13601HIGHGlib: integer overflow in in g_escape_uri_string()EPSS 0.3%CVE-2026-6682HIGHFatFs Integer Overflow in FAT32 Volume MountEPSS 0.3%CVE-2024-32913CRITICALIn wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote cEPSS 0.3%CVE-2023-28908MEDIUMInteger Overflow in Non-Fragmented Data ReceptionEPSS 0.3%CVE-2026-28493MEDIUMImageMagick has a Integer Overflow leading to out of bounds write in SIXEL decoderEPSS 0.3%CVE-2026-21689MEDIUMiccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cppEPSS 0.3%CVE-2026-79223HIGHInteger overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a craftEPSS 0.3%CVE-2021-41197MEDIUMCrashes due to overflow and `CHECK`-fail in ops with large tensor shapesEPSS 0.3%CVE-2023-38560MEDIUMGhostscript: integer overflow in pcl/pl/plfont.c:418 in pl_glyph_nameEPSS 0.3%CVE-2025-66030MEDIUMnode-forge ASN.1 OID Integer TruncationEPSS 0.3%