Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2025-66030MEDIUMnode-forge ASN.1 OID Integer TruncationEPSS 0.3%CVE-2021-3782MEDIUMAn internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. The reference count isEPSS 0.3%CVE-2026-5476LOWNASA cFS cfe_tbl_passthru_codec.c CFE_TBL_ValidateCodecLoadSize integer overflowEPSS 0.3%CVE-2021-0701—In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allEPSS 0.3%CVE-2026-11088CRITICALInteger overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to poteEPSS 0.3%CVE-2025-55554MEDIUMpytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().EPSS 0.3%CVE-2024-41858HIGHAdobe InCopy has an integer overflow vulnerability when parsing SVG fileEPSS 0.3%CVE-2026-75863HIGHPhotoshop Desktop | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-75771HIGHPhotoshop Desktop | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-34640HIGHMedia Encoder | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-81987HIGHAcrobat Reader | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-47940HIGHLightroom Classic | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-34644HIGHAfter Effects | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-48342HIGHBridge | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-75862HIGHPhotoshop Desktop | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-82007HIGHPhotoshop Desktop | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2018-9352MEDIUMIn ihevcd_allocate_dynamic_bufs of ihevcd_api.c there is a possible resource exhaustion due to integer overflow. This could lead to remote dEPSS 0.3%CVE-2026-50310MEDIUMWindows Human Interface Device Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-45527MEDIUMIn convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer oveEPSS 0.3%CVE-2026-47223MEDIUMNanaZip: Heap out-of-bounds read in NanaZip AVB hashtree descriptor parser via 32-bit unsigned integer overflowEPSS 0.3%