Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2026-19028MEDIUMHDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds readEPSS 0.2%CVE-2026-46655HIGHvirtio-win: Integer overflow causing a heap overflow in Viosock driverEPSS 0.2%CVE-2024-21845LOWDsoftbus has an integer overflow vulnerabilityEPSS 0.2%CVE-2026-82737MEDIUMAsh.Vector wraps the 16-bit dimension header for vectors over 65,535 elements, corrupting data and crashing readsEPSS 0.2%CVE-2026-64765HIGHAn integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOSEPSS 0.2%CVE-2026-64766HIGHAn integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOSEPSS 0.2%CVE-2026-10722MEDIUMcilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflowEPSS 0.2%CVE-2026-43905HIGHOpenImageIO: JPEG2000 (OpenJPH) signed integer overflow in buffer allocationEPSS 0.2%CVE-2026-33327HIGHPossible integer overflow leading to potential heap-based buffer overflowEPSS 0.2%CVE-2026-44605MEDIUMRpm: heap buffer overflow in ndb slot table parsingEPSS 0.2%CVE-2026-0140MEDIUMIn RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosEPSS 0.2%CVE-2022-22078MEDIUMDenial of service in BOOT when partition size for a particular partition is requested due to integer overflow when blocks are calculated in EPSS 0.2%CVE-2025-59800MEDIUMIn Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer oveEPSS 0.2%CVE-2026-88914MEDIUMGstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parserEPSS 0.2%CVE-2026-42627MEDIUMIn Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model fileEPSS 0.2%CVE-2026-56407MEDIUMlibexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.EPSS 0.2%CVE-2026-56406MEDIUMlibexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.EPSS 0.2%CVE-2026-52834HIGHjxl-oxide: Out-of-bounds writes due to integer overflow in jxl-grid on 32-bit platformsEPSS 0.2%CVE-2026-71261HIGHdr_wav.h W64 CUE Chunk Metadata Parsing Integer Overflow Leading to Heap Buffer Overflow on 32-bit BuildsEPSS 0.2%CVE-2026-43780HIGHAn integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macEPSS 0.2%