Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2026-0161HIGHIn numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote escEPSS 0.2%CVE-2026-0151HIGHIn IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code executEPSS 0.2%CVE-2026-19167LOWInteger overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak EPSS 0.2%CVE-2024-53161MEDIUMEDAC/bluefield: Fix potential integer overflowEPSS 0.2%CVE-2023-25516HIGH NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause an integer overEPSS 0.2%CVE-2026-91746MEDIUMInteger overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted EPSS 0.2%CVE-2026-40244HIGHOpenEXR has integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589)EPSS 0.2%CVE-2024-57953MEDIUMrtc: tps6594: Fix integer overflow on 32bit systemsEPSS 0.2%CVE-2025-30327HIGHInCopy | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2026-33020HIGHlibsixel: Integer Overflow in write_png_to_file() leads to Heap-based Buffer OverflowEPSS 0.2%CVE-2022-49885MEDIUMACPI: APEI: Fix integer overflow in ghes_estatus_pool_init()EPSS 0.2%CVE-2023-34406LOWAn issue was discovered on Mercedes Benz NTG 6. A possible integer overflow exists in the user data import/export function of NTG (New TelemEPSS 0.2%CVE-2026-34963HIGHbarebox EFI PE Loader Memory Safety VulnerabilitiesEPSS 0.2%CVE-2024-57890MEDIUMRDMA/uverbs: Prevent integer overflow issueEPSS 0.2%CVE-2021-29605HIGHInteger overflow in TFLite memory allocationEPSS 0.2%CVE-2025-61800HIGHDimension | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2025-49531HIGHIllustrator | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2025-7982HIGHAshlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-21321HIGHAfter Effects | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2024-31047LOWAn issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the converEPSS 0.2%