Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2024-51480HIGHRedisTimeSeries Integer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-81878MEDIUMradare2: Integer overflow causes heap out-of-bounds write in radare2 PYC parserEPSS 0.2%CVE-2026-46331HIGHnet/sched: fix pedit partial COW leading to page cache corruptionEPSS 0.2%CVE-2026-42144MEDIUMCImg Library: Integer overflow in PNM size check bypasses memory guard (_load_pnm)EPSS 0.2%CVE-2025-12035MEDIUMBluetooth: Integer Overflow in Bluetooth Classic (BR/EDR) L2CAPEPSS 0.2%CVE-2026-43627HIGHllama.cpp b1283–b9058 Integer Overflow in llama_batch_init() FunctionEPSS 0.2%CVE-2024-50270MEDIUMmm/damon/core: avoid overflow in damon_feed_loop_next_input()EPSS 0.2%CVE-2026-11299MEDIUMInteger overflow in Fonts in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information fromEPSS 0.2%CVE-2026-39855MEDIUMosslsigncode has an Integer Underflow in PE Page Hash Calculation Can Cause Out-of-Bounds ReadEPSS 0.2%CVE-2025-22001HIGHaccel/qaic: Fix integer overflow in qaic_validate_req()EPSS 0.2%CVE-2023-28185MEDIUMAn integer overflow was addressed through improved input validation. This issue is fixed in tvOS 16.4, macOS Big Sur 11.7.5, iOS 16.4 and iPEPSS 0.2%CVE-2026-61722MEDIUMFluidSynth: DLS Articulation Chunk Integer OverflowEPSS 0.2%CVE-2026-32845MEDIUMjkuhlmann / cgltf <= 1.15 Sparse Accessor Validation Integer OverflowEPSS 0.2%CVE-2026-45130MEDIUMVim: Heap Buffer Overflow in spell file loadingEPSS 0.2%CVE-2026-15108MEDIUMInteger overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious EPSS 0.2%CVE-2026-3308HIGHCVE-2026-3308EPSS 0.2%CVE-2026-57432HIGHPerl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpackEPSS 0.2%CVE-2026-3284MEDIUMlibvips extract.c vips_extract_area_build integer overflowEPSS 0.2%CVE-2026-52969HIGHKVM: Reject wrapped offset in kvm_reset_dirty_gfn()EPSS 0.2%CVE-2026-53763LOWOP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks authentication guaranteeEPSS 0.2%