Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2026-43780HIGHAn integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macEPSS 0.2%CVE-2026-48690HIGHFastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packetEPSS 0.2%CVE-2024-34740HIGHIn attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer oveEPSS 0.2%CVE-2026-59183MEDIUMOpenEXR: Signed Integer Overflow Leading to Out-of-Bounds Memory Access in Deep Tile DecodingEPSS 0.2%CVE-2026-65969MEDIUMOpenImageIO: TGA-to-GIF palette split signed overflow causes SIGSEGVEPSS 0.2%CVE-2025-48172MEDIUMCHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultaEPSS 0.2%CVE-2026-84548MEDIUMAn integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TahEPSS 0.2%CVE-2025-64894MEDIUMDNG SDK | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2026-16661HIGHPower System Integer OverflowEPSS 0.2%CVE-2026-16933HIGHPower System Integer OverflowEPSS 0.2%CVE-2024-52059MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags.EPSS 0.2%CVE-2026-4731HIGHAn Integer Overflow Vulnerability in artraweditor/ARTEPSS 0.2%CVE-2026-56403MEDIUMlibexpat before 2.8.2 has an integer overflow in storeAtts.EPSS 0.2%CVE-2026-6045MEDIUMHeap buffer overflow in EMF+ gradient brush importEPSS 0.2%CVE-2026-6103MEDIUMPhar TAR phar_tar_number() Integer Overflow - Archive Entry InjectionEPSS 0.2%CVE-2026-44637HIGHlibsixel: integer overflow in parserEPSS 0.2%CVE-2026-84620HIGHAn integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macEPSS 0.2%CVE-2026-86139MEDIUMIn libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.EPSS 0.2%CVE-2026-21347HIGHBridge | Integer Overflow or Wraparound (CWE-190)EPSS 0.2%CVE-2026-65413MEDIUMAn integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TahEPSS 0.2%