Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2026-24808HIGHA possible integer overflow vulnerability in RawTherapee/RawTherapeeEPSS 0.1%CVE-2022-42533HIGHIn shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local EPSS 0.1%CVE-2026-16174HIGHNetskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool OverflowEPSS 0.1%CVE-2022-33219CRITICALInteger Overflow to Buffer Overflow in AutomotiveEPSS 0.1%CVE-2026-18445MEDIUMInteger Overflow Vulnerability Resulting in an Out of Bounds Write in NI LabVIEWEPSS 0.1%CVE-2026-86138MEDIUMIn libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.EPSS 0.1%CVE-2025-52538HIGHImproper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resultingEPSS 0.1%CVE-2026-96749HIGHHeap out-of-bounds write via signed size overflow in BSON document encodingEPSS 0.1%CVE-2026-22801MEDIUMLIBPNG has an integer truncation causing heap buffer over-read in png_image_write_*EPSS 0.1%CVE-2024-23372HIGHInteger Overflow or Wraparound in GraphicsEPSS 0.1%CVE-2026-27781LOWkernel_liteos_a has an integer overflow vulnerabilityEPSS 0.1%CVE-2025-48515MEDIUMInsufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwEPSS 0.1%CVE-2026-16416CRITICALInteger overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape viaEPSS 0.1%CVE-2017-13318MEDIUMIn HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remoEPSS 0.1%CVE-2025-22836HIGHInteger overflow or wraparound in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authEPSS 0.1%CVE-2024-13614MEDIUMKaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky EEPSS 0.1%CVE-2026-56404MEDIUMlibexpat before 2.8.2 has an integer overflow in addBinding.EPSS 0.1%CVE-2026-56410MEDIUMxmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.EPSS 0.1%CVE-2026-56411MEDIUMxmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.EPSS 0.1%CVE-2024-33035HIGHInteger Overflow or Wraparound in DisplayEPSS 0.1%