Weaknesses of type CWE-190

1,670 results

Estouro ou envolvimento de inteiro

Ocorre quando uma operação aritmética produz um resultado maior (ou menor, em caso de sinal) do que o tipo de dado consegue representar, causando truncamento ou envolvimento para valores inesperados. Um atacante explora isso para contornar validações, causar alocações de memória inválidas ou alterar lógica de negócio.

Example

Um servidor calcula tamanho de buffer como `size = quantidade * 100`. Se quantidade for próxima ao máximo de um inteiro de 32 bits, a multiplicação estoura e retorna um valor pequeno, levando a alocação insuficiente e buffer overflow posterior.

How to mitigate

Valide limites antes de operações aritméticas (verifique se o resultado cabe no tipo), use tipos de dado maiores quando possível, ou aplique bibliotecas de aritmética segura que detectam estouro em tempo de execução.

CVE-2026-16517LOWLibarchive: libarchive: signed integer overflow in archive_write_zip_headerEPSS 0.1%CVE-2025-36936HIGHIn GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow. This could lead to locaEPSS 0.1%CVE-2026-0194HIGHIn multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege wiEPSS 0.1%CVE-2024-47024HIGHIn vring_size of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to an integer overflow. This couEPSS 0.1%CVE-2026-0043MEDIUMIn multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This couldEPSS 0.1%CVE-2026-0131HIGHIn RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to local escalation of privEPSS 0.1%CVE-2026-0079MEDIUMIn multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This couldEPSS 0.1%CVE-2026-25290HIGHInteger Overflow or Wraparound in OOBMEPSS 0.1%CVE-2026-0150HIGHIn ExecuteGraph command handler of EdgeTPU firmware, there is a possible out of bounds write due to an integer overflow. This could lead to EPSS 0.1%CVE-2026-11290MEDIUMInteger overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a mEPSS 0.1%