Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2023-25667MEDIUMTensorFlow vulnerable to segfault when opening multiframe gifEPSS 0.3%CVE-2026-88351CRITICALAn integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePEPSS 0.3%CVE-2024-52035HIGHAn integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted EPSS 0.3%CVE-2023-4722MEDIUMInteger Overflow or Wraparound in gpac/gpacEPSS 0.3%CVE-2026-23833LOWESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API componentEPSS 0.3%CVE-2023-53156MEDIUMThe transpose crate before 0.2.3 for Rust allows an integer overflow via input_width and input_height arguments.EPSS 0.3%CVE-2025-65803MEDIUMAn integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and before allows attackers to cause a Denial of Service (EPSS 0.3%CVE-2026-48444MEDIUMCAI Content Credentials | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2021-3428—A flaw was found in the Linux kernel. A denial of service problem is identified if an extent tree is corrupted in a crafted ext4 filesystem EPSS 0.3%CVE-2025-66499HIGHFoxit PDF Reader PDF Parsing Heap-Based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-3607—An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs whEPSS 0.3%CVE-2023-1900HIGHA vulnerability within the Avira network protection feature allowed an attacker with local execution rights to cause an overflow. This couldEPSS 0.3%CVE-2023-23559HIGHIn rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.EPSS 0.3%CVE-2022-49451HIGHfirmware: arm_scmi: Fix list protocols enumeration in the base protocolEPSS 0.3%CVE-2021-22677—An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network may lead to issues such as a denial-of-servEPSS 0.3%CVE-2026-59089MEDIUMGimp: gimp: denial of service via integer overflow in playstation tim loaderEPSS 0.3%CVE-2025-20710HIGHIn wlan AP driver, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) escalatEPSS 0.3%CVE-2024-23851MEDIUMcopy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes, and crash, because oEPSS 0.3%CVE-2025-15278HIGHFontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-73086HIGHnanoid: Integer Overflow or WraparoundEPSS 0.3%