CWE-190— Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.— MITRE CWE catalog
3,599 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-190page 70 of 72
- CVE-2026-64911HIGHCVSS 7.8EG 7.82026-08-11
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-65346HIGHCVSS 8.8EG 8.82026-08-17
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to arbitrary code…
- CVE-2026-65390HIGHCVSS 8.8EG 8.82026-09-14
An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead…
- CVE-2026-65391HIGHCVSS 8.8EG 8.82026-09-14
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content …
- CVE-2026-65408MEDIUMCVSS 5.5EG 5.52026-09-14
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected sys…
- CVE-2026-65413MEDIUMCVSS 5.5EG 5.52026-09-14
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause a denial of service.
- CVE-2026-65423HIGHCVSS 8.8EG 8.82026-07-30
An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.
- CVE-2026-65799HIGHCVSS 7.8EG 7.82026-08-11
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
- CVE-2026-65814HIGHCVSS 7.8EG 7.82026-08-11
Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-65969MEDIUMCVSS 5.5EG 5.52026-09-18
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that is process…
- CVE-2026-66039HIGHCVSS 7.8EG 8.82026-07-24
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value…
- CVE-2026-6664HIGHCVSS 7.5EG 7.52026-05-09
An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malformed SCRAM authentication packet.
- CVE-2026-66757MEDIUMCVSS 5.5EG 5.52026-07-27
A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted fil…
- CVE-2026-66758HIGHCVSS 7.8EG 7.82026-07-27
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their…
- CVE-2026-6679HIGHCVSS 7.5EG 7.52026-06-25
A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when computing the length of the ACK record-number list, causing an…
- CVE-2026-6682HIGHCVSS 7.6EG 7.62026-07-01
In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlled file-size metadata and unsafe read lengths in downstream callers. This maps to CWE-190 (…
- CVE-2026-67376HIGHCVSS 7.5EG 7.52026-09-08
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.
- CVE-2026-67384HIGHCVSS 8.8EG 8.82026-09-08
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67641MEDIUMCVSS 6.5EG 6.52026-09-08
Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
- CVE-2026-6773HIGHCVSS 7.5EG 7.52026-04-21
Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
- CVE-2026-6783MEDIUMCVSS 5.3EG 5.32026-04-21
Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
- CVE-2026-68552MEDIUMCVSS 5.3EG 5.32026-08-19
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t len vari…
- CVE-2026-68832HIGHCVSS 7.8EG 7.82026-09-08
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-68889HIGHCVSS 7.1EG 7.12026-09-08
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69242HIGHCVSS 8.4EG 8.42026-08-20
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflo…
- CVE-2026-69266HIGHCVSS 8.8EG 8.82026-09-08
Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-69298HIGHCVSS 7.8EG 7.82026-09-08
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69329HIGHCVSS 7.5EG 7.52026-09-08
Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network.
- CVE-2026-69373MEDIUMCVSS 6.7EG 6.72026-09-08
Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
- CVE-2026-69407HIGHCVSS 7.8EG 7.82026-09-08
Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69408CRITICALCVSS 9.8EG 9.82026-09-08
Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-69419HIGHCVSS 8.8EG 8.82026-08-20
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
- CVE-2026-69469MEDIUMCVSS 6.6EG 6.62026-09-08
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.
- CVE-2026-69499HIGHCVSS 8.8EG 8.82026-09-08
Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-69584HIGHCVSS 7.8EG 7.82026-09-08
Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69586CRITICALCVSS 9.8EG 9.82026-09-08
Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
- CVE-2026-69594HIGHCVSS 7.8EG 7.82026-09-08
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69608HIGHCVSS 7.8EG 7.82026-09-08
Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
- CVE-2026-69631HIGHCVSS 7.5EG 7.52026-09-08
Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network.
- CVE-2026-69707HIGHCVSS 7.8EG 7.82026-09-08
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69734MEDIUMCVSS 6.5EG 6.52026-09-08
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
- CVE-2026-69738HIGHCVSS 7.8EG 7.82026-09-08
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69742HIGHCVSS 8.8EG 8.82026-09-08
Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
- CVE-2026-69846HIGHCVSS 8.2EG 8.22026-09-08
Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
- CVE-2026-70329HIGHCVSS 8.8EG 8.82026-08-11
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- CVE-2026-70351HIGHCVSS 8.8EG 8.82026-09-08
Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
- CVE-2026-70462MEDIUMCVSS 6.5EG 6.52026-08-13
rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive (zero …
- CVE-2026-70572HIGHCVSS 7.8EG 7.82026-09-08
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-70581HIGHCVSS 7.8EG 7.82026-09-08
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-70628HIGHCVSS 7.8EG 7.82026-08-06
FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted …
Map vulnerabilities like CWE-190 to your infrastructure
EchelonGraph correlates every CVE — across CWE-190 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →