Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2026-56408MEDIUMlibexpat before 2.8.2 has an integer overflow in copyString.EPSS 0.1%CVE-2026-84965MEDIUMHeap write primitive via size round-up wrap during JSON parsing on 32-bit buildsEPSS 0.1%CVE-2026-40385MEDIUMIn libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes EPSS 0.1%CVE-2025-0005HIGHImproper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resultingEPSS 0.1%CVE-2026-56405MEDIUMlibexpat before 2.8.2 has an integer overflow in getAttributeId.EPSS 0.1%CVE-2026-20753HIGHInteger overflow in the UEFI firmware for the Slim Bootloader may allow an escalation of privilege. System software adversary with a privileEPSS 0.1%CVE-2026-62343MEDIUMImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is providedEPSS 0.1%CVE-2023-29146HIGHThe utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes truncate the hashed data iEPSS 0.1%CVE-2022-39907MEDIUMInteger overflow vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perEPSS 0.1%CVE-2026-40448MEDIUMPotential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large tensors in Samsung OEPSS 0.1%CVE-2025-14098HIGHAvira antivirus engine heap buffer OOB write when scanning a malformed MS-DOS executable fileEPSS 0.1%CVE-2026-62946MEDIUMImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit buildsEPSS 0.1%CVE-2026-49919HIGHIn tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escaEPSS 0.1%CVE-2023-33032CRITICALInteger Overflow or Wraparound in TZ Secure OSEPSS 0.1%CVE-2022-39105MEDIUMIn sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kerneEPSS 0.1%CVE-2026-10268MEDIUMjanet-lang janet marsh.c unmarshal_one_fiber integer overflowEPSS 0.1%CVE-2022-42764MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2026-56711HIGHVLC media player 3.0.0 through 3.0.23 memory corruption vulnerabilityEPSS 0.1%CVE-2022-42763MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2026-56409MEDIUMxmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.EPSS 0.1%