Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2026-65390HIGHAn integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS EPSS 0.4%CVE-2026-17705HIGHInteger overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via EPSS 0.4%CVE-2026-19174HIGHInteger overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a cEPSS 0.4%CVE-2026-65391HIGHAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1EPSS 0.4%CVE-2026-82076HIGHInteger Overflow in Query Planner Leads to Unbounded Memory Allocation and Denial of Service in MongoDB ServerEPSS 0.4%CVE-2026-90473MEDIUMmsgpack-java through 0.9.12 Integer Overflow via MAP32EPSS 0.4%CVE-2026-91728CRITICALInteger overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a EPSS 0.4%CVE-2026-11725HIGHIBM MQ queue manager is vulnerable to privilege escalationEPSS 0.4%CVE-2025-52935CRITICALInteger Overflow or Wraparound vulnerability in dragonflydb/dragonflyEPSS 0.4%CVE-2026-73558MEDIUMvLLM: Cross-User Data Leak VulnerabilityEPSS 0.4%CVE-2025-65865HIGHAn integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.EPSS 0.4%CVE-2026-84536MEDIUMAn integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaEPSS 0.4%CVE-2026-6668HIGHInteger overflow causes an infinite loop in packet buffer growth in PgBouncerEPSS 0.4%CVE-2026-79292HIGHInteger overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process toEPSS 0.4%CVE-2024-36474HIGHAn integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (EPSS 0.4%CVE-2026-13063MEDIUMlibmongocrypt Improper Input Validation Leading to Process TerminationEPSS 0.4%CVE-2026-88412MEDIUMAn integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows attackers to cause EPSS 0.4%CVE-2025-62467HIGHWindows Projected File System Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-20795HIGHAnimate has an arbitrary code execution vulnerability when parsing svg filesEPSS 0.4%CVE-2026-54226MEDIUMApache Kvrocks: RESTORE IntSet Integer Overflow Leads to Remote DoSEPSS 0.4%