Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2026-24808HIGHA possible integer overflow vulnerability in RawTherapee/RawTherapeeEPSS 0.1%CVE-2022-42533HIGHIn shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local EPSS 0.1%CVE-2026-16174HIGHNetskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool OverflowEPSS 0.1%CVE-2022-33219CRITICALInteger Overflow to Buffer Overflow in AutomotiveEPSS 0.1%CVE-2026-18445MEDIUMInteger Overflow Vulnerability Resulting in an Out of Bounds Write in NI LabVIEWEPSS 0.1%CVE-2026-86138MEDIUMIn libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.EPSS 0.1%CVE-2025-52538HIGHImproper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resultingEPSS 0.1%CVE-2026-96749HIGHHeap out-of-bounds write via signed size overflow in BSON document encodingEPSS 0.1%CVE-2026-22801MEDIUMLIBPNG has an integer truncation causing heap buffer over-read in png_image_write_*EPSS 0.1%CVE-2024-23372HIGHInteger Overflow or Wraparound in GraphicsEPSS 0.1%CVE-2026-27781LOWkernel_liteos_a has an integer overflow vulnerabilityEPSS 0.1%CVE-2025-48515MEDIUMInsufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwEPSS 0.1%CVE-2026-16416CRITICALInteger overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape viaEPSS 0.1%CVE-2017-13318MEDIUMIn HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remoEPSS 0.1%CVE-2025-22836HIGHInteger overflow or wraparound in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authEPSS 0.1%CVE-2024-13614MEDIUMKaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky EEPSS 0.1%CVE-2026-56404MEDIUMlibexpat before 2.8.2 has an integer overflow in addBinding.EPSS 0.1%CVE-2026-56410MEDIUMxmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.EPSS 0.1%CVE-2026-56411MEDIUMxmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.EPSS 0.1%CVE-2024-33035HIGHInteger Overflow or Wraparound in DisplayEPSS 0.1%