Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2025-66030MEDIUMnode-forge ASN.1 OID Integer TruncationEPSS 0.3%CVE-2021-3782MEDIUMAn internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. The reference count isEPSS 0.3%CVE-2026-5476LOWNASA cFS cfe_tbl_passthru_codec.c CFE_TBL_ValidateCodecLoadSize integer overflowEPSS 0.3%CVE-2021-0701—In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allEPSS 0.3%CVE-2026-11088CRITICALInteger overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to poteEPSS 0.3%CVE-2025-55554MEDIUMpytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().EPSS 0.3%CVE-2024-41858HIGHAdobe InCopy has an integer overflow vulnerability when parsing SVG fileEPSS 0.3%CVE-2026-75863HIGHPhotoshop Desktop | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-75771HIGHPhotoshop Desktop | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-34640HIGHMedia Encoder | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-81987HIGHAcrobat Reader | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-47940HIGHLightroom Classic | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-34644HIGHAfter Effects | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-48342HIGHBridge | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-75862HIGHPhotoshop Desktop | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-82007HIGHPhotoshop Desktop | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2018-9352MEDIUMIn ihevcd_allocate_dynamic_bufs of ihevcd_api.c there is a possible resource exhaustion due to integer overflow. This could lead to remote dEPSS 0.3%CVE-2026-50310MEDIUMWindows Human Interface Device Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-45527MEDIUMIn convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer oveEPSS 0.3%CVE-2026-47223MEDIUMNanaZip: Heap out-of-bounds read in NanaZip AVB hashtree descriptor parser via 32-bit unsigned integer overflowEPSS 0.3%