CWE-190— Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.— MITRE CWE catalog
3,599 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-190page 67 of 72
- CVE-2026-48354MEDIUMCVSS 6.2EG 6.22026-07-14
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-ser…
- CVE-2026-48387MEDIUMCVSS 6.2EG 6.22026-08-11
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-ser…
- CVE-2026-48444MEDIUMCVSS 6.2EG 6.22026-08-11
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-ser…
- CVE-2026-48445MEDIUMCVSS 6.2EG 6.22026-08-11
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-ser…
- CVE-2026-48486HIGHCVSS 7.5EG 7.52026-09-03
Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in BlockServiceImpl.applyBlock() allowed a miner to receive an arbitra…
- CVE-2026-48502HIGHCVSS 7.5EG 7.52026-06-22
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp exte…
- CVE-2026-48690HIGHCVSS 7.1EG 7.12026-05-26
FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memory_size_in_bytes as 'buffer_size_in_packe…
- CVE-2026-48691CRITICALCVSS 9.8EG 9.82026-05-26
FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attribute_length as 'sizeof(bgp_as_path_segm…
- CVE-2026-48933HIGHCVSS 7.5EG 7.52026-06-26
A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
- CVE-2026-49168MEDIUMCVSS 6.8EG 6.82026-07-14
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.
- CVE-2026-49346HIGHCVSS 7.1EG 7.12026-06-19
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in `de265_image_get_buffer()` (`libde265/…
- CVE-2026-49416HIGHCVSS 7.8EG 7.82026-06-27
The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subsequent initializati…
- CVE-2026-49510MEDIUMCVSS 6.1EG 6.12026-06-04
Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.
- CVE-2026-49800HIGHCVSS 7.8EG 7.82026-07-14
Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
- CVE-2026-4985MEDIUMCVSS 4.3EG 4.32026-03-27
A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the file src/cgif.c of the component GIF Image Handler. The manipulation of the argument width/height leads to integer over…
- CVE-2026-49919HIGHCVSS 7.8EG 7.82026-09-08
In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
- CVE-2026-49927HIGHCVSS 7.8EG 7.82026-09-08
In multiple locations, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-50142HIGHCVSS 7.5EG 7.52026-08-18
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequence…
- CVE-2026-50161CRITICALCVSS 9.3EG 9.32026-08-18
libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket fram…
- CVE-2026-50278MEDIUMCVSS 6.5EG 6.52026-08-21
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing ICC…
- CVE-2026-50298MEDIUMCVSS 6.8EG 6.82026-07-14
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
- CVE-2026-50299MEDIUMCVSS 6.8EG 6.82026-07-14
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.
- CVE-2026-50306HIGHCVSS 7.8EG 7.82026-07-14
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
- CVE-2026-50310MEDIUMCVSS 4.7EG 4.72026-07-14
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.
- CVE-2026-50347HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
- CVE-2026-50435HIGHCVSS 7.8EG 7.82026-07-14
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
- CVE-2026-5121CRITICALCVSS 9.8EG 9.82026-03-30
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to …
- CVE-2026-51536CRITICALCVSS 9.1EG 9.12026-07-13
In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream length calculated as an int is passed to…
- CVE-2026-52491HIGHCVSS 8.4EG 8.42026-08-25
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component
- CVE-2026-52492HIGHCVSS 7.8EG 7.82026-08-24
An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF i…
- CVE-2026-52722HIGHCVSS 7.1EG 7.12026-06-15
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds re…
- CVE-2026-52834HIGHCVSS 7.3EG 7.32026-07-02
jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid a…
- CVE-2026-52948MEDIUMCVSS 5.5EG 5.52026-06-24
In the Linux kernel, the following vulnerability has been resolved: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl While fuzzing with Syzkaller, a persistent `schedule_timeout: wrong timeout value` warning was observed, accompan…
- CVE-2026-52969HIGHCVSS 7.0EG 7.02026-06-24
In the Linux kernel, the following vulnerability has been resolved: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() kvm_reset_dirty_gfn() guards the gfn range with if (!memslot || (offset + __fls(mask)) >= memslot->npages) return…
- CVE-2026-52972HIGHCVSS 5.5EG 7.02026-06-24
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Cap AEAD AD length to 0x80000000 In order to prevent arithmetic overflows when checking the TX buffer size, cap the associated data length to 0x80000000.
- CVE-2026-53021MEDIUMCVSS 5.5EG 5.52026-06-24
In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix integer overflow in UNMAP bounds check sbc_execute_unmap() checks LBA + range does not exceed the device capacity, but does not guard against LBA…
- CVE-2026-53059HIGHCVSS 7.8EG 7.82026-06-24
In the Linux kernel, the following vulnerability has been resolved: dm log: fix out-of-bounds write due to region_count overflow The local variable region_count in create_log_context() is declared as unsigned int (32-bit), but dm_sector_…
- CVE-2026-53068HIGHCVSS 7.1EG 7.12026-06-24
In the Linux kernel, the following vulnerability has been resolved: drm/komeda: fix integer overflow in AFBC framebuffer size check The AFBC framebuffer size validation calculates the minimum required buffer size by adding the AFBC paylo…
- CVE-2026-53432HIGHCVSS 7.5EG 7.52026-06-30
fzf is vulnerable to Integer Overflow leading to crash in FuzzyMatchV2 function. When input line length is approximately 2,200,000 bytes and pattern length is 999 bytes, the product overflows. The Go runtime detects the invalid slice b…
- CVE-2026-53466MEDIUMCVSS 6.5EG 6.52026-07-01
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is rea…
- CVE-2026-53482HIGHCVSS 7.5EG 7.52026-07-08
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Integer overflo…
- CVE-2026-53705HIGHCVSS 7.6EG 7.62026-06-15
A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame(…
- CVE-2026-53763LOWCVSS 3.8EG 3.82026-07-06
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.0.0 and prior to version 4.11.0, 32-bit integer overflo…
- CVE-2026-53910LOWCVSS 2.1EG 2.12026-07-22
diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used …
- CVE-2026-54109HIGHCVSS 7.8EG 7.82026-07-14
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
- CVE-2026-54115HIGHCVSS 7.8EG 7.82026-07-14
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
- CVE-2026-54124HIGHCVSS 7.8EG 7.82026-07-14
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
- CVE-2026-54226MEDIUMCVSS 6.4EG 6.42026-06-25
A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
- CVE-2026-54240HIGHCVSS 7.4EG 7.42026-09-11
libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflow …
- CVE-2026-54241HIGHCVSS 7.4EG 7.42026-09-11
libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16…
Map vulnerabilities like CWE-190 to your infrastructure
EchelonGraph correlates every CVE — across CWE-190 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →