Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2023-46246MEDIUMInteger Overflow in :history command in VimEPSS 0.4%CVE-2026-37537HIGHcollin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (2023-03-08) contains an integer underflow leading to out-of-boEPSS 0.4%CVE-2024-57254HIGHAn integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a crafted squashfs filesyEPSS 0.4%CVE-2024-57255HIGHAn integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with an inode size of EPSS 0.4%CVE-2023-38653HIGHMultiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode dict parsing functionality of GTKWave 3.3.115. A speciallEPSS 0.4%CVE-2023-38652HIGHMultiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode dict parsing functionality of GTKWave 3.3.115. A speciallEPSS 0.4%CVE-2026-95619HIGHGcc: libstdc++ integer overflow in `new` operatorEPSS 0.4%CVE-2026-42580MEDIUMNetty: HTTP Request Smuggling due to incorrect chunk size parsingEPSS 0.4%CVE-2026-16529HIGHPcp: pcp: denial of service due to signed integer overflowEPSS 0.4%CVE-2026-66758HIGHGimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits imagesEPSS 0.4%CVE-2026-21688HIGHiccDEV has Type Confusion in SIccCalcOp::ArgsPushed() at IccProfLib/IccMpeCalc.cppEPSS 0.4%CVE-2026-21485HIGHiccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()EPSS 0.4%CVE-2025-48174MEDIUMIn libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.EPSS 0.4%CVE-2026-18304HIGHGIMP TIF File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-18305HIGHGIMP TIF File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-18671MEDIUMIBM i is Affected By Multiple Vulnerabilities in NetServerEPSS 0.4%CVE-2025-48816HIGHHID Class Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-49176HIGHXorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in big requests extensionEPSS 0.4%CVE-2026-54920NONEOpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil image resizeEPSS 0.4%CVE-2025-14933HIGHNSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Execution VulnerabilityEPSS 0.4%