Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2022-28197MEDIUMNVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_mount function, where Insufficient validation of untrusted datEPSS 0.2%CVE-2026-34544HIGHOpenEXR: integer overflow to OOB write in uncompress_b44_impl()EPSS 0.2%CVE-2025-10456HIGHBluetooth: Semi-Arbitrary ability to make the BLE Target send disconnection requestsEPSS 0.2%CVE-2026-14757MEDIUMradareorg radare2 cmd_anal.inc core_anal_bytes integer overflowEPSS 0.2%CVE-2025-33219HIGHNVIDIA Display Driver for Linux contains a vulnerability in the NVIDIA kernel module where an attacker could cause an integer overflow or wrEPSS 0.2%CVE-2025-33218HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where an attacker could cause an intEPSS 0.2%CVE-2024-53111HIGHmm/mremap: fix address wraparound in move_page_tables()EPSS 0.2%CVE-2026-48065MEDIUMpam_usb: Unchecked integer multiplication before xmalloc() in conf.c allows heap-based buffer overflow on 32-bit targetsEPSS 0.2%CVE-2023-28903LOWAn integer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to causEPSS 0.2%CVE-2025-61807HIGHSubstance3D - Stager | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2025-64783HIGHDNG SDK | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2025-61803HIGHSubstance3D - Stager | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2026-33019HIGHlibsixel: Integer overflow leads to Out-of-bounds Read in img2sixelEPSS 0.2%CVE-2026-14787MEDIUMradareorg radare2 pb Print cmd_print.inc cmd_print integer overflowEPSS 0.2%CVE-2025-7985HIGHAshlar-Vellum Cobalt VC6 File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-21997MEDIUMxsk: fix an integer overflow in xp_create_and_assign_umem()EPSS 0.2%CVE-2025-21963MEDIUMcifs: Fix integer overflow while processing acdirmax mount optionEPSS 0.2%CVE-2025-21964MEDIUMcifs: Fix integer overflow while processing acregmax mount optionEPSS 0.2%CVE-2026-75148MEDIUMcgltf 1.15 Integer Overflow via cgltf_validate() Accessor Bounds CheckEPSS 0.2%CVE-2025-21962MEDIUMcifs: Fix integer overflow while processing closetimeo mount optionEPSS 0.2%