Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2022-28197MEDIUMNVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_mount function, where Insufficient validation of untrusted datEPSS 0.2%CVE-2026-34544HIGHOpenEXR: integer overflow to OOB write in uncompress_b44_impl()EPSS 0.2%CVE-2025-10456HIGHBluetooth: Semi-Arbitrary ability to make the BLE Target send disconnection requestsEPSS 0.2%CVE-2026-14757MEDIUMradareorg radare2 cmd_anal.inc core_anal_bytes integer overflowEPSS 0.2%CVE-2025-33219HIGHNVIDIA Display Driver for Linux contains a vulnerability in the NVIDIA kernel module where an attacker could cause an integer overflow or wrEPSS 0.2%CVE-2025-33218HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where an attacker could cause an intEPSS 0.2%CVE-2024-53111HIGHmm/mremap: fix address wraparound in move_page_tables()EPSS 0.2%CVE-2026-48065MEDIUMpam_usb: Unchecked integer multiplication before xmalloc() in conf.c allows heap-based buffer overflow on 32-bit targetsEPSS 0.2%CVE-2023-28903LOWAn integer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to causEPSS 0.2%CVE-2025-61807HIGHSubstance3D - Stager | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2025-64783HIGHDNG SDK | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2025-61803HIGHSubstance3D - Stager | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2026-33019HIGHlibsixel: Integer overflow leads to Out-of-bounds Read in img2sixelEPSS 0.2%CVE-2026-14787MEDIUMradareorg radare2 pb Print cmd_print.inc cmd_print integer overflowEPSS 0.2%CVE-2025-7985HIGHAshlar-Vellum Cobalt VC6 File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-21997MEDIUMxsk: fix an integer overflow in xp_create_and_assign_umem()EPSS 0.2%CVE-2025-21963MEDIUMcifs: Fix integer overflow while processing acdirmax mount optionEPSS 0.2%CVE-2025-21964MEDIUMcifs: Fix integer overflow while processing acregmax mount optionEPSS 0.2%CVE-2026-75148MEDIUMcgltf 1.15 Integer Overflow via cgltf_validate() Accessor Bounds CheckEPSS 0.2%CVE-2025-21962MEDIUMcifs: Fix integer overflow while processing closetimeo mount optionEPSS 0.2%