Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2026-40962MEDIUMFFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.cEPSS 0.2%CVE-2026-65408MEDIUMAn integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macEPSS 0.2%CVE-2024-6638MEDIUMInteger Overflow Vulnerability Reading TDMS Files in LabVIEWEPSS 0.2%CVE-2026-55373MEDIUMOpenEXR: OpenEXRUtil SampleCountChannel endEdit() can loop forever on UINT_MAX sample countsEPSS 0.2%CVE-2025-2574LOWOut-of-bounds array write in Xpdf 4.05 due to incorrect integer overflow checkingEPSS 0.2%CVE-2026-72854MEDIUMmsgpack-c Integer Overflow in msgpack_unpacker_expand_buffer Causes a False-Success Undersized ReservationEPSS 0.2%CVE-2024-36328HIGHInteger overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss of integrity or avaiEPSS 0.2%CVE-2023-53309MEDIUMdrm/radeon: Fix integer overflow in radeon_cs_parser_initEPSS 0.2%CVE-2026-21486HIGHUse After Free and Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write in iccDEVEPSS 0.2%CVE-2026-19321MEDIUMPower System Integer OverflowEPSS 0.2%CVE-2024-21851LOWDsoftbus has an integer overflow vulnerabilityEPSS 0.2%CVE-2023-20507LOWAn integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resulting in loss of data inEPSS 0.2%CVE-2026-42798MEDIUMLittle CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.EPSS 0.2%CVE-2026-43894MEDIUMjq: Wild stack write via signed-integer overflow in decNumber D2U() macroEPSS 0.2%CVE-2026-33328MEDIUMPossible integer overflow on 32-bit systems when reading GIF imagesEPSS 0.2%CVE-2026-45258HIGHMultiple vulnerabilities in the sound(4) mmap pathEPSS 0.2%CVE-2026-47714MEDIUMlibheif has integer overflow in inline mask size calculation that causes undersized buffer allocationEPSS 0.2%CVE-2026-49416HIGHInteger overflow in vt(4) CONS_HISTORY ioctlEPSS 0.2%CVE-2026-0031HIGHIn multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalatEPSS 0.2%CVE-2026-0028HIGHIn __pkvm_host_share_guest of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local esEPSS 0.2%