Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2025-20710HIGHIn wlan AP driver, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) escalatEPSS 0.3%CVE-2024-45778MEDIUMGrub2: fs/bfs: integer overflow in the bfs parser.EPSS 0.3%CVE-2024-40635MEDIUMcontainerd has an integer overflow in User ID handlingEPSS 0.3%CVE-2026-24814CRITICALA integer overflow in swoole/swoole-srcEPSS 0.3%CVE-2018-9348HIGHIn SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote denial of service due to resource exhausEPSS 0.3%CVE-2026-55254MEDIUMNCalc: Denial of Service via Unbounded and Non-Terminating Factorial EvaluationEPSS 0.3%CVE-2024-45779MEDIUMGrub2: fs/bfs: integer overflow leads to heap oob read in the bfs parserEPSS 0.3%CVE-2023-40022HIGHRizin vulnerable to Integer Overflow in C++ demangler logicEPSS 0.3%CVE-2026-33471CRITICALnimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncationEPSS 0.3%CVE-2026-16554MEDIUMInteger Overflow Leading to Heap Buffer Overflow in cJSONEPSS 0.3%CVE-2026-40447MEDIUMInteger overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affects Escargot: 97e8115aEPSS 0.3%CVE-2024-40784HIGHAn integer overflow was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 1EPSS 0.3%CVE-2026-48354MEDIUMCAI Content Credentials | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-48387MEDIUMCAI Content Credentials | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-48445MEDIUMCAI Content Credentials | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-34671MEDIUMCAI Content Credentials | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-34680MEDIUMCAI Content Credentials | Integer Overflow or Wraparound (CWE-190)EPSS 0.3%CVE-2026-18078MEDIUMIBM i is Affected By Denial of Service Vulnerability in Save Restore []EPSS 0.3%CVE-2022-47092HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is contains an Integer overflow vulnerability in gf_hevc_read_sps_bs_internal function of media_tools/EPSS 0.3%CVE-2026-11044MEDIUMInteger overflow in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive informatiEPSS 0.3%