Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2025-11463HIGHAshlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-5916LOWLibarchive: integer overflow while reading warc files at archive_read_support_format_warc.cEPSS 0.2%CVE-2026-77219MEDIUMGNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image LoaderEPSS 0.2%CVE-2026-92248HIGHGimp: integer overflow when generating a thumbnail preview for a psd fileEPSS 0.2%CVE-2024-52557MEDIUMdrm: zynqmp_dp: Fix integer overflow in zynqmp_dp_rate_get()EPSS 0.2%CVE-2026-52972HIGHcrypto: af_alg - Cap AEAD AD length to 0x80000000EPSS 0.2%CVE-2026-42199MEDIUMGrid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined BehaviorEPSS 0.2%CVE-2026-61723MEDIUMFluidSynth: DLS ptbl Chunk Integer OverflowEPSS 0.2%CVE-2022-20597HIGHIn ppmpu_set of ppmpu.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege with no additiEPSS 0.2%CVE-2026-18917HIGHLibvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflowEPSS 0.2%CVE-2025-0587LOWArkcompiler Ets Runtime has an integer overflow vulnerabilityEPSS 0.2%CVE-2026-82908CRITICALMSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflowEPSS 0.2%CVE-2022-20598HIGHIn sec_media_protect of media.c, there is a possible EoP due to an integer overflow. This could lead to local escalation of privilege of secEPSS 0.2%CVE-2026-27691MEDIUMiccDEV has SIO in parse3DTable() at iccFromCube.cpp Line 218EPSS 0.2%CVE-2026-86314MEDIUMInteger overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote atEPSS 0.2%CVE-2025-46333HIGHz2d OOB composition could lead to invalid memory access and corruptionEPSS 0.2%CVE-2026-27940HIGHllama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 FixEPSS 0.2%CVE-2025-22851MEDIUMLiteos_A has an integer overflow vulnerabilityEPSS 0.2%CVE-2026-55093MEDIUMtract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model loadEPSS 0.2%CVE-2024-21845LOWDsoftbus has an integer overflow vulnerabilityEPSS 0.2%