Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2026-21354MEDIUMDNG SDK | Integer Overflow or Wraparound (CWE-190)EPSS 0.1%CVE-2026-3196MEDIUMQemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocationEPSS 0.1%CVE-2026-40450MEDIUMInteger overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and memory corruption fEPSS 0.1%CVE-2026-40449MEDIUMInteger overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in Samsung Open Source OEPSS 0.1%CVE-2026-41666MEDIUMInteger overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during loop state propagationEPSS 0.1%CVE-2026-41667MEDIUMInteger overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant EPSS 0.1%CVE-2026-41664MEDIUMInteger overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapesEPSS 0.1%CVE-2026-30937MEDIUMImageMagick has a heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculationEPSS 0.1%CVE-2024-28044LOWLiteos-A has an integer overflow vulnerabilityEPSS 0.1%CVE-2026-41665MEDIUMInteger overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for largEPSS 0.1%CVE-2026-7162HIGHSuccessful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected softwarEPSS 0.1%CVE-2026-53059MEDIUMdm log: fix out-of-bounds write due to region_count overflowEPSS 0.1%CVE-2026-92259MEDIUMInteger overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directoEPSS 0.1%CVE-2026-44636HIGHlibsixel: integer overflow in encoderEPSS 0.1%CVE-2024-36320HIGHInteger Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to loss of confidentialEPSS 0.1%CVE-2022-20454MEDIUMIn fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privileEPSS 0.1%CVE-2018-9481MEDIUMIn bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote infoEPSS 0.1%CVE-2026-24875HIGHInteger overflow in modizerEPSS 0.1%CVE-2025-23241HIGHInteger overflow or wraparound in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authEPSS 0.1%CVE-2026-24808HIGHA possible integer overflow vulnerability in RawTherapee/RawTherapeeEPSS 0.1%