Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2026-40962MEDIUMFFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.cEPSS 0.2%CVE-2026-65408MEDIUMAn integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macEPSS 0.2%CVE-2024-6638MEDIUMInteger Overflow Vulnerability Reading TDMS Files in LabVIEWEPSS 0.2%CVE-2026-55373MEDIUMOpenEXR: OpenEXRUtil SampleCountChannel endEdit() can loop forever on UINT_MAX sample countsEPSS 0.2%CVE-2025-2574LOWOut-of-bounds array write in Xpdf 4.05 due to incorrect integer overflow checkingEPSS 0.2%CVE-2026-72854MEDIUMmsgpack-c Integer Overflow in msgpack_unpacker_expand_buffer Causes a False-Success Undersized ReservationEPSS 0.2%CVE-2024-36328HIGHInteger overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss of integrity or avaiEPSS 0.2%CVE-2023-53309MEDIUMdrm/radeon: Fix integer overflow in radeon_cs_parser_initEPSS 0.2%CVE-2026-21486HIGHUse After Free and Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write in iccDEVEPSS 0.2%CVE-2026-19321MEDIUMPower System Integer OverflowEPSS 0.2%CVE-2024-21851LOWDsoftbus has an integer overflow vulnerabilityEPSS 0.2%CVE-2023-20507LOWAn integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resulting in loss of data inEPSS 0.2%CVE-2026-42798MEDIUMLittle CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.EPSS 0.2%CVE-2026-43894MEDIUMjq: Wild stack write via signed-integer overflow in decNumber D2U() macroEPSS 0.2%CVE-2026-33328MEDIUMPossible integer overflow on 32-bit systems when reading GIF imagesEPSS 0.2%CVE-2026-45258HIGHMultiple vulnerabilities in the sound(4) mmap pathEPSS 0.2%CVE-2026-47714MEDIUMlibheif has integer overflow in inline mask size calculation that causes undersized buffer allocationEPSS 0.2%CVE-2026-49416HIGHInteger overflow in vt(4) CONS_HISTORY ioctlEPSS 0.2%CVE-2026-0031HIGHIn multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalatEPSS 0.2%CVE-2026-0028HIGHIn __pkvm_host_share_guest of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local esEPSS 0.2%