CWE-190— Integer Overflow or Wraparound
2,793 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-190page 17 of 56
- CVE-2018-17897CRITICALCVSS 9.8EG 9.82018-10-17
LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execution.
- CVE-2018-17958HIGHCVSS 7.5EG 7.52018-10-09
Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
- CVE-2018-17962HIGHCVSS 7.5EG 7.52018-10-09
Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.
- CVE-2018-17963CRITICALCVSS 9.8EG 9.82018-10-09
qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.
- CVE-2018-18206HIGHCVSS 7.5EG 7.52018-10-10
In the client in Bytom before 1.0.6, checkTopicRegister in p2p/discover/net.go does not prevent negative idx values, leading to a crash.
- CVE-2018-18311CRITICALCVSS 9.8EG 9.82018-12-07
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
- CVE-2018-18341HIGHCVSS 8.8EG 8.82018-12-11
An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2018-18356HIGHCVSS 8.8EG 8.82018-12-11
An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2018-18438MEDIUMCVSS 5.5EG 5.52018-10-19
Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value.
- CVE-2018-18483HIGHCVSS 7.8EG 7.82018-10-18
The get_count function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31, allows remote attackers to cause a denial of service (malloc called with the result of an integer-overflowing calculation) or possibly have unspec…
- CVE-2018-18498CRITICALCVSS 9.8EG 9.82019-02-28
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects T…
- CVE-2018-18650MEDIUMCVSS 5.5EG 5.52018-10-25
An issue was discovered in Xpdf 4.00. XRef::readXRefStream in XRef.cc allows attackers to launch a denial of service (Integer Overflow) via a crafted /Size value in a pdf file, as demonstrated by pdftohtml. This is mainly caused by the pro…
- CVE-2018-18665HIGHCVSS 7.5EG 7.52018-12-28
The mintToken function of Nexxus (NXX) aka NexxusToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
- CVE-2018-18666HIGHCVSS 7.5EG 7.52018-12-28
The mintToken function of SwftCoin (SWFTC) aka SwftCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
- CVE-2018-18667HIGHCVSS 7.5EG 7.52018-12-28
The mintToken function of Pylon (PYLNT) aka PylonToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value, a related issue to CVE-2018-11812.
- CVE-2018-18749MEDIUMCVSS 5.5EG 5.52018-10-29
data-tools through 2017-07-26 has an Integer Overflow leading to an incorrect end value for the write_wchars function.
- CVE-2018-18928CRITICALCVSS 9.8EG 9.82018-11-04
International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificString() in i18n/number_decimalquantity.cpp.
- CVE-2018-19107MEDIUMCVSS 6.5EG 6.52018-11-08
In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD image file.
- CVE-2018-19199CRITICALCVSS 9.8EG 9.82018-11-12
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.
- CVE-2018-19665MEDIUMCVSS 5.7EG 5.72018-12-06
The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.
- CVE-2018-19932MEDIUMCVSS 5.5EG 5.52018-12-07
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.
- CVE-2018-20177CRITICALCVSS 9.8EG 9.82019-03-15
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() and results in memory corruption and possibly even a remote code execution.
- CVE-2018-20330HIGHCVSS 8.8EG 8.82018-12-21
The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.
- CVE-2018-20346HIGHCVSS 8.1EG 8.12018-12-21
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrar…
- CVE-2018-20406HIGHCVSS 7.5EG 7.52018-12-23
Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during a "resize to twice the size" attempt. This issue might cause memory exhaustion, but is only relevant if the pickle for…
- CVE-2018-20506HIGHCVSS 8.1EG 8.12019-04-03
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attac…
- CVE-2018-20545HIGHCVSS 8.8EG 8.82018-12-28
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
- CVE-2018-20546HIGHCVSS 8.1EG 8.12018-12-28
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
- CVE-2018-20671MEDIUMCVSS 5.5EG 5.52019-01-04
load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.
- CVE-2018-20673MEDIUMCVSS 5.5EG 5.52019-01-04
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based…
- CVE-2018-20787MEDIUMCVSS 5.5EG 5.52019-02-25
The ft5x46 touchscreen driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer overflow and OOPS because of missing checks of the size argument in tpdbg_write in drivers/input/touchscreen/…
- CVE-2018-20788MEDIUMCVSS 5.5EG 5.52019-02-25
drivers/leds/leds-aw2023.c in the led driver for custom Linux kernels on the Xiaomi Redmi 6pro daisy-o-oss phone has several integer overflows because of a left-shifting operation when the right-hand operand can be equal to or greater than…
- CVE-2018-20820MEDIUMCVSS 5.5EG 5.52019-04-23
read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file.
- CVE-2018-20847HIGHCVSS 8.8EG 8.82019-06-26
An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.
- CVE-2018-21009HIGHCVSS 8.8EG 8.82019-09-05
Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc.
- CVE-2018-21054CRITICALCVSS 9.8EG 9.82020-04-08
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9820 in all Platforms, M(6.0) except MSM8909 SC77xx/9830 exynos3470/5420, N(7.0) except MSM8939, N(7.1) except MSM8996 SDM6xx/M6737T softwar…
- CVE-2018-21089CRITICALCVSS 9.8EG 9.82020-04-08
An issue was discovered on Samsung mobile devices with N(7.x) (MT6755/MT6757 Mediatek models) software. Bootloader has an integer overflow that leads to arbitrary code execution via the download offset control. The Samsung ID is SVE-2017-1…
- CVE-2018-3577HIGHCVSS 7.5EG 7.52018-07-06
While processing fragments, when the fragment count becomes very large, an integer overflow leading to a buffer overflow can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) befor…
- CVE-2018-3586CRITICALCVSS 9.8EG 9.82018-07-06
An integer overflow to buffer overflow vulnerability exists in the ADSPRPC heap manager in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
- CVE-2018-4249HIGHCVSS 7.8EG 7.82018-06-08
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves pktmnglr_ipfilter_input in com.apple.packe…
- CVE-2018-5000MEDIUMCVSS 6.5EG 6.52018-07-09
Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure.
- CVE-2018-5095CRITICALCVSS 9.8EG 9.82018-06-11
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This v…
- CVE-2018-5122CRITICALCVSS 9.8EG 9.82018-06-11
A potential integer overflow in the "DoCrypt" function of WebCrypto was identified. If a means was found of exploiting it, it could result in an out-of-bounds write. This vulnerability affects Firefox < 58.
- CVE-2018-5144HIGHCVSS 7.3EG 7.32018-06-11
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
- CVE-2018-5159CRITICALCVSS 9.8EG 9.82018-06-11
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web cont…
- CVE-2018-5294MEDIUMCVSS 6.5EG 6.52018-01-08
In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.
- CVE-2018-5295MEDIUMCVSS 5.5EG 5.52018-01-08
In PoDoFo 0.9.5, there is an integer overflow in the PdfXRefStreamParserObject::ParseStream function (base/PdfXRefStreamParserObject.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf fi…
- CVE-2018-5309MEDIUMCVSS 5.5EG 5.52018-01-09
In PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function (base/PdfObjectStreamParserObject.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a …
- CVE-2018-5709HIGHCVSS 7.5EG 7.52018-01-16
An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a "u4" variable to it, which is for …
- CVE-2018-5727MEDIUMCVSS 6.5EG 6.52018-01-16
In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_encode_cblks function (openjp2/t1.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
Map vulnerabilities like CWE-190 to your infrastructure
EchelonGraph correlates every CVE — across CWE-190 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →