Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2026-43780HIGHAn integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macEPSS 0.2%CVE-2026-48690HIGHFastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packetEPSS 0.2%CVE-2024-34740HIGHIn attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer oveEPSS 0.2%CVE-2026-59183MEDIUMOpenEXR: Signed Integer Overflow Leading to Out-of-Bounds Memory Access in Deep Tile DecodingEPSS 0.2%CVE-2026-65969MEDIUMOpenImageIO: TGA-to-GIF palette split signed overflow causes SIGSEGVEPSS 0.2%CVE-2025-48172MEDIUMCHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultaEPSS 0.2%CVE-2026-84548MEDIUMAn integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TahEPSS 0.2%CVE-2025-64894MEDIUMDNG SDK | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2026-16661HIGHPower System Integer OverflowEPSS 0.2%CVE-2026-16933HIGHPower System Integer OverflowEPSS 0.2%CVE-2024-52059MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags.EPSS 0.2%CVE-2026-4731HIGHAn Integer Overflow Vulnerability in artraweditor/ARTEPSS 0.2%CVE-2026-56403MEDIUMlibexpat before 2.8.2 has an integer overflow in storeAtts.EPSS 0.2%CVE-2026-6045MEDIUMHeap buffer overflow in EMF+ gradient brush importEPSS 0.2%CVE-2026-6103MEDIUMPhar TAR phar_tar_number() Integer Overflow - Archive Entry InjectionEPSS 0.2%CVE-2026-44637HIGHlibsixel: integer overflow in parserEPSS 0.2%CVE-2026-84620HIGHAn integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macEPSS 0.2%CVE-2026-86139MEDIUMIn libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.EPSS 0.2%CVE-2026-21347HIGHBridge | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2026-65413MEDIUMAn integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TahEPSS 0.2%