Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2025-11463HIGHAshlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-5916LOWLibarchive: integer overflow while reading warc files at archive_read_support_format_warc.cEPSS 0.2%CVE-2026-77219MEDIUMGNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image LoaderEPSS 0.2%CVE-2026-92248HIGHGimp: integer overflow when generating a thumbnail preview for a psd fileEPSS 0.2%CVE-2024-52557MEDIUMdrm: zynqmp_dp: Fix integer overflow in zynqmp_dp_rate_get()EPSS 0.2%CVE-2026-52972HIGHcrypto: af_alg - Cap AEAD AD length to 0x80000000EPSS 0.2%CVE-2026-42199MEDIUMGrid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined BehaviorEPSS 0.2%CVE-2026-61723MEDIUMFluidSynth: DLS ptbl Chunk Integer OverflowEPSS 0.2%CVE-2022-20597HIGHIn ppmpu_set of ppmpu.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege with no additiEPSS 0.2%CVE-2026-18917HIGHLibvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflowEPSS 0.2%CVE-2025-0587LOWArkcompiler Ets Runtime has an integer overflow vulnerabilityEPSS 0.2%CVE-2026-82908CRITICALMSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflowEPSS 0.2%CVE-2022-20598HIGHIn sec_media_protect of media.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege of secEPSS 0.2%CVE-2026-27691MEDIUMiccDEV has SIO in parse3DTable() at iccFromCube.cpp Line 218EPSS 0.2%CVE-2026-86314MEDIUMInteger overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote atEPSS 0.2%CVE-2025-46333HIGHz2d OOB composition could lead to invalid memory access and corruptionEPSS 0.2%CVE-2026-27940HIGHllama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 FixEPSS 0.2%CVE-2025-22851MEDIUMLiteos_A has an integer overflow vulnerabilityEPSS 0.2%CVE-2026-55093MEDIUMtract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model loadEPSS 0.2%CVE-2024-21845LOWDsoftbus has an integer overflow vulnerabilityEPSS 0.2%