Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2022-47092HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is contains an Integer overflow vulnerability in gf_hevc_read_sps_bs_internal function of media_tools/EPSS 0.3%CVE-2025-43556HIGHAnimate | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2025-0678HIGHGrub2: squash4: integer overflow may lead to heap based out-of-bounds write when reading dataEPSS 0.3%CVE-2025-43547HIGHBridge | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-29776LOWFreeRDP has an Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core LibraryEPSS 0.3%CVE-2025-30325HIGHPhotoshop Desktop | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2024-57262HIGHIn barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via a crafted ext4 fileEPSS 0.3%CVE-2024-57261HIGHIn barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-57258.EPSS 0.3%CVE-2024-50610LOWGSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When params.n_tries is neEPSS 0.3%CVE-2025-54895HIGHSPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-78465HIGHGimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bitEPSS 0.3%CVE-2024-33024HIGHInteger Overflow or Wraparound in WLAN HostEPSS 0.3%CVE-2025-9688LOWMupen64Plus is_viewer.c write_is_viewer integer overflowEPSS 0.3%CVE-2022-49727MEDIUMipv6: Fix signed integer overflow in l2tp_ip6_sendmsgEPSS 0.3%CVE-2021-27504HIGHTexas Instruments FREERTOS Integer Overflow or WraparoundEPSS 0.3%CVE-2021-27502HIGHTexas Instruments TI-RTOS Integer Overflow or WraparoundEPSS 0.3%CVE-2022-49643HIGHima: Fix a potential integer overflow in ima_appraise_measurementEPSS 0.3%CVE-2023-42752MEDIUMKernel: integer overflow in igmpv3_newpack leading to exploitable memory accessEPSS 0.3%CVE-2025-46597HIGHBitcoin Core 0.13.0 through 29.x has an integer overflow.EPSS 0.3%CVE-2024-52919MEDIUMBitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messEPSS 0.3%