Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2024-53145MEDIUMum: Fix potential integer overflow during physmem setupEPSS 0.2%CVE-2025-22080HIGHfs/ntfs3: Prevent integer overflow in hdr_first_de()EPSS 0.2%CVE-2024-20047MEDIUMIn battery, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System eEPSS 0.2%CVE-2026-42311HIGHPillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow)EPSS 0.2%CVE-2025-29088MEDIUMIn SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (applicatEPSS 0.2%CVE-2026-25210MEDIUMIn libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow chEPSS 0.2%CVE-2025-22081HIGHfs/ntfs3: Fix a couple integer overflows on 32bit systemsEPSS 0.2%CVE-2022-31600HIGHNVIDIA DGX A100 contains a vulnerability in SBIOS in the SmmCore, where a user with high privileges can chain another vulnerability to this EPSS 0.2%CVE-2026-27622HIGHOpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB writeEPSS 0.2%CVE-2024-7867LOWInteger overflow and divide-by-zero in Xpdf 4.05 due to bogus page box coordinatesEPSS 0.2%CVE-2024-53107HIGHfs/proc/task_mmu: prevent integer overflow in pagemap_scan_get_args()EPSS 0.2%CVE-2024-38805MEDIUMiSCSI Remote Memory Corruption and Denial of ServiceEPSS 0.2%CVE-2021-41195MEDIUMCrash in `tf.math.segment_*` operationsEPSS 0.2%CVE-2023-29144LOWMalwarebytes 1.0.14 for Linux doesn't properly compute signatures in some scenarios. This allows a bypass of detection.EPSS 0.2%CVE-2021-26346MEDIUMFailure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in tEPSS 0.2%CVE-2026-72852HIGHdarknet Integer Overflow in Convolutional Layer Buffer Sizing Leads to Heap Buffer OverflowEPSS 0.2%CVE-2024-21783LOWInteger overflow for some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of prEPSS 0.2%CVE-2024-57938MEDIUMnet/sctp: Prevent autoclose integer overflow in sctp_association_init()EPSS 0.2%CVE-2025-54259HIGHSubstance3D - Modeler | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2026-44663MEDIUMOpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflowEPSS 0.2%