Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2022-49643HIGHima: Fix a potential integer overflow in ima_appraise_measurementEPSS 0.3%CVE-2026-89157MEDIUMPCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.EPSS 0.3%CVE-2025-62231HIGHXorg: xmayland: value overflow in xkbsetcompatmap()EPSS 0.3%CVE-2026-0148HIGHIn multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer overflow. This could leadEPSS 0.3%CVE-2022-49404MEDIUMRDMA/hfi1: Fix potential integer multiplication overflow errorsEPSS 0.3%CVE-2024-36613MEDIUMFFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in aEPSS 0.3%CVE-2021-27243HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-48919. An attacker muEPSS 0.3%CVE-2021-22636HIGHTexas Instruments TI-RTOS Integer Overflow or WraparoundEPSS 0.3%CVE-2021-27429HIGHTexas Instruments TI-RTOS Integer Overflow or WraparoundEPSS 0.3%CVE-2025-1235MEDIUMWAGO: Switches affected by year 2k38 problemEPSS 0.3%CVE-2026-69242HIGHlibvips: Integer overflow leading to heap buffer overflow leading to possible attacker-controlled mmap-resident writeEPSS 0.3%CVE-2026-33855MEDIUMInteger Overflow or Wraparound in MolotovCherry Android-ImageMagick7EPSS 0.3%CVE-2025-11152HIGHSandbox escape due to integer overflow in the Graphics: Canvas2D componentEPSS 0.3%CVE-2024-20046MEDIUMIn battery, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege with SyEPSS 0.3%CVE-2020-15137MEDIUMInteger overflow in HoRNDISEPSS 0.3%CVE-2024-36121MEDIUM netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats NoncesEPSS 0.3%CVE-2024-31416MEDIUMThe Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reporEPSS 0.3%CVE-2025-2021HIGHAshlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-2023HIGHAshlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-42257MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to infEPSS 0.3%