Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2026-40915MEDIUMGimp: gimp: heap buffer overflow due to integer overflow in fits image loaderEPSS 0.4%CVE-2024-51737HIGHRediSearch Integer Overflow with LIMIT or KNN arguments can lead to RCEEPSS 0.4%CVE-2024-51540HIGHDell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of ECS. An authenticatEPSS 0.4%CVE-2025-54804MEDIUMRussh is missing an overflow check during channel windows adjustEPSS 0.4%CVE-2025-58715HIGHWindows Speech Runtime Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2022-48480HIGHInteger overflow vulnerability in some phones. Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.4%CVE-2023-25662HIGHTensorFlow vulnerable to integer overflow in EditDistanceEPSS 0.4%CVE-2026-54241HIGHlibde265: SAO sequential filter heap buffer overflow via signed integer overflowEPSS 0.4%CVE-2023-21704HIGHMicrosoft ODBC Driver for SQL Server Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-23417HIGHWindows Partition Management Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-54240HIGHlibde265: Pixel accessor signed integer overflow causes heap OOB read/writeEPSS 0.4%CVE-2026-0861HIGHInteger overflow in memalign leads to heap corruptionEPSS 0.4%CVE-2025-55068HIGHDover Fueling Solutions ProGauge MagLink LX4 Devices Integer Overflow or WraparoundEPSS 0.4%CVE-2023-4424HIGHbt: hci: DoS and possible RCEEPSS 0.4%CVE-2022-2454HIGHInteger Overflow or Wraparound in gpac/gpacEPSS 0.4%CVE-2026-48112MEDIUMGHSL-2026-122 7-Zip Ar SYMDEF OOB ReadEPSS 0.4%CVE-2026-88372HIGHlibsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.EPSS 0.4%CVE-2026-24889MEDIUMsoroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64EPSS 0.4%CVE-2026-58472MEDIUMGNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute EncodingEPSS 0.4%CVE-2026-33596LOWTCP backend stream ID overflowEPSS 0.4%