Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2026-28532MEDIUMFRRouting < 10.5.3 Integer Overflow in OSPF TLV Parser FunctionsEPSS 0.4%CVE-2024-57256HIGHAn integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a craftedEPSS 0.4%CVE-2026-53466MEDIUMImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflowEPSS 0.4%CVE-2023-38651HIGHMultiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode times parsing functionality of GTKWave 3.3.115. A specialEPSS 0.4%CVE-2023-29364HIGHWindows Authentication Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-38650HIGHMultiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode times parsing functionality of GTKWave 3.3.115. A specialEPSS 0.4%CVE-2026-83601MEDIUMNetdata: Streaming protocol dimension slot has no upper-bound guard, allowing integer overflow and out-of-bounds writeEPSS 0.4%CVE-2021-33631MEDIUMKernel crash in EXT4 filesystemEPSS 0.4%CVE-2024-47416HIGHAnimate | Integer Overflow or Wraparound (CWE-190)EPSS 0.4%CVE-2024-34139HIGHAdobe Bridge has an integer overflow vulnerability when parsing SVG fileEPSS 0.4%CVE-2025-22471MEDIUMDell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacEPSS 0.4%CVE-2022-0998—An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validateEPSS 0.4%CVE-2026-55400MEDIUMCVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send sEPSS 0.4%CVE-2019-10142HIGHA flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parametEPSS 0.4%CVE-2026-62897HIGH.NET Framework Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-58749LOWWAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT modeEPSS 0.4%CVE-2026-33298HIGHllama.cpp has a Heap Buffer Overflow via Integer Overflow in GGUF Tensor ParsingEPSS 0.4%CVE-2022-48468MEDIUMprotobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.EPSS 0.4%CVE-2024-34121HIGHIllustrator | Integer Overflow or Wraparound (CWE-190)EPSS 0.4%CVE-2026-47857MEDIUMReactor Core windowTimeout fair-backpressure stream hang due to 20-bit index wrap-aroundEPSS 0.4%