Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2026-0128MEDIUMIn RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote informatioEPSS 0.2%CVE-2026-21673HIGHiccDEV has Integer Overflow/Underflow in CIccXmlArrayType::ParseTextCountNum()EPSS 0.2%CVE-2024-3757LOWArkcompiler runtime has an integer overflow vulnerabilityEPSS 0.2%CVE-2025-46285HIGHAn integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26EPSS 0.2%CVE-2026-52491HIGHAn issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c:EPSS 0.2%CVE-2021-29601MEDIUMInteger overflow in TFLite concatentationEPSS 0.2%CVE-2026-20446MEDIUMIn sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker EPSS 0.2%CVE-2026-81666MEDIUMCorosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systemsEPSS 0.2%CVE-2022-49748MEDIUMperf/x86/amd: fix potential integer overflow on shift of a intEPSS 0.2%CVE-2022-49749MEDIUMi2c: designware: use casting of u64 in clock multiplication to avoid overflowEPSS 0.2%CVE-2026-31641HIGHrxrpc: Fix RxGK token loading to check boundsEPSS 0.2%CVE-2024-50177MEDIUMdrm/amd/display: fix a UBSAN warning in DML2.1EPSS 0.2%CVE-2021-29523LOWCHECK-fail in AddManySparseToTensorsMapEPSS 0.2%CVE-2026-14758MEDIUMradareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflowEPSS 0.2%CVE-2026-14761MEDIUMradareorg radare2 str.c r_str_append integer overflowEPSS 0.2%CVE-2026-14786MEDIUMradareorg radare2 str.c r_str_word_get0set integer overflowEPSS 0.2%CVE-2021-29584LOWCHECK-fail due to integer overflowEPSS 0.2%CVE-2026-52492HIGHAn integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heEPSS 0.2%CVE-2024-44198MEDIUMAn integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18,EPSS 0.2%CVE-2026-21353HIGHDNG SDK | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%