Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2022-47489MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2026-55351HIGHIn VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additioEPSS 0.1%CVE-2023-20682MEDIUMIn wlan, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System exEPSS 0.1%CVE-2023-20662MEDIUMIn wlan, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System exEPSS 0.1%CVE-2023-20661MEDIUMIn wlan, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System exEPSS 0.1%CVE-2023-20663MEDIUMIn wlan, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System exEPSS 0.1%CVE-2021-0884HIGHIn PVRSRVBridgePhysmemImportSparseDmaBuf of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that EPSS 0.1%CVE-2021-0882HIGHIn PVRSRVBridgeRGXKickSync of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow ouEPSS 0.1%CVE-2021-0875HIGHIn PVRSRVBridgeChangeSparseMem of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could alloEPSS 0.1%CVE-2023-20660MEDIUMIn wlan, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execEPSS 0.1%CVE-2021-0873HIGHIn PVRSRVBridgeRGXKickRS of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-EPSS 0.1%CVE-2021-0880HIGHIn PVRSRVBridgeRGXKickTA3D of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow ouEPSS 0.1%CVE-2021-0874HIGHIn PVRSRVBridgeDevicememHistorySparseChange of the PowerVR kernel driver, a missing size check means there is a possible integer overflow thEPSS 0.1%CVE-2021-0872HIGHIn PVRSRVBridgeRGXKickVRDM of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow ouEPSS 0.1%CVE-2021-0885HIGHIn PVRSRVBridgeSyncPrimOpTake of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allowEPSS 0.1%CVE-2021-0883HIGHIn PVRSRVBridgeCacheOpQueue of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow oEPSS 0.1%CVE-2021-0878HIGHIn PVRSRVBridgeServerSyncGetStatus of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could EPSS 0.1%CVE-2021-0879HIGHIn PVRSRVBridgeRGXTDMSubmitTransfer of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that couldEPSS 0.1%CVE-2021-0881HIGHIn PVRSRVBridgeRGXKickCDM of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow outEPSS 0.1%CVE-2025-47323HIGHInteger Overflow or Wraparound in AudioEPSS 0.1%