Fallos del tipo CWE-190

1670 resultados

Estouro ou Envolvimento de Inteiro

Ocorre quando uma operação aritmética produz um resultado que excede a capacidade máxima (ou mínima) do tipo de dado inteiro, causando um envolvimento (wraparound) silencioso para um valor inesperado. O perigo está em decisões lógicas baseadas nesse valor corrompido — validações de tamanho, cálculos de alocação de memória ou verificações de limites falham silenciosamente.

Ejemplo

Um aplicativo valida que um tamanho de upload é menor que 2GB comparando `size < 2147483648`. Um atacante fornece um valor de 2147483648 bytes em um inteiro de 32 bits com sinal; o valor sofre wraparound para -2147483648, passa na validação, e a alocação subsequente falha ou aloca memória insuficiente, levando a corrupção de heap.

Cómo mitigar

Use verificações explícitas antes de operações: validar se a adição de dois números não vai ultrapassar o limite antes de somar, preferir tipos sem sinal quando o contexto permite valores positivos apenas, ou usar bibliotecas/linguagens com aritmética segura que lançam exceções em overflow (como Python ou linguagens modernas com verificação de bounds).

CVE-2022-38680MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2021-0876HIGHIn PVRSRVBridgePhysmemNewRamBackedLockedPMR of the PowerVR kernel driver, a missing size check means there is a possible integer overflow thEPSS 0.1%CVE-2025-54631MEDIUMVulnerability of insufficient data length verification in the partition module. Impact: Successful exploitation of this vulnerability may afEPSS 0.1%CVE-2025-20803MEDIUMIn dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege if a malicious acEPSS 0.1%CVE-2025-20807MEDIUMIn dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious EPSS 0.1%CVE-2022-47322MEDIUMIn wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2023-32828MEDIUMIn vpu, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System exeEPSS 0.1%CVE-2024-34733HIGHIn DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to locEPSS 0.1%CVE-2025-20722MEDIUMIn gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a maliEPSS 0.1%CVE-2023-32881MEDIUMIn battery, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with SystEPSS 0.1%CVE-2023-32829MEDIUMIn apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2025-47351HIGHInteger Overflow or Wraparound in DSP ServiceEPSS 0.1%CVE-2024-20025MEDIUMIn da, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execEPSS 0.1%CVE-2018-9482MEDIUMIn intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflow. This could lead to local information EPSS 0.1%CVE-2026-11281MEDIUMInteger overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive iEPSS 0.1%CVE-2023-32823MEDIUMIn rpmb , there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2025-20653MEDIUMIn da, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure, if an attacker haEPSS 0.1%CVE-2025-36900MEDIUMIn lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer overflow. This could lead to local escalatioEPSS 0.1%CVE-2026-18462HIGHInteger Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation.EPSS 0.1%CVE-2025-47365HIGHInteger Overflow or Wraparound in Automotive PlatformEPSS 0.1%