CWE-195
16 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-195page 1 of 1
- CVE-2011-3045HIGHCVSS 8.8EG 8.82012-03-22
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or p…
- CVE-2020-1913HIGHCVSS 8.1EG 8.12020-09-09
An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potential RCE via crafted JavaScript. Note that…
- CVE-2020-6096HIGHCVSS 8.1EG 8.12020-04-01
An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter …
- CVE-2022-43663HIGHCVSS 8.1EG 9.82023-03-20
An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a buffer overflow. An attacker can send a malicious packet to t…
- CVE-2023-28063MEDIUMCVSS 6.7EG 6.72024-02-06
Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.
- CVE-2023-33034HIGHCVSS 7.8EG 7.82023-10-03
Memory corruption while parsing the ADSP response command.
- CVE-2023-3635MEDIUMCVSS 5.9EG 5.92023-07-12
GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
- CVE-2023-5184HIGHCVSS 7.0EG 7.02023-09-27
Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the Zephyr IPM drivers.
- CVE-2024-25388HIGHCVSS 8.4EG 8.42024-03-27
drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an integer signedness error and resultant buffer overflow.
- CVE-2025-24792MEDIUMCVSS 4.4EG 4.42025-01-29
Snowflake PHP PDO Driver is a driver that uses the PHP Data Objects (PDO) extension to connect to the Snowflake database. Snowflake discovered and remediated a vulnerability in the Snowflake PHP PDO Driver where executing unsupported queri…
- CVE-2025-30646MEDIUMCVSS 6.5EG 6.52025-04-09
A Signed to Unsigned Conversion Error vulnerability in the Layer 2 Control Protocol daemon (l2cpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated adjacent attacker sending a specifically malfor…
- CVE-2025-49847HIGHCVSS 8.8EG 8.82025-06-17
llama.cpp is an inference of several LLM models in C/C++. Prior to version b5662, an attacker‐supplied GGUF model vocabulary can trigger a buffer overflow in llama.cpp’s vocabulary‐loading code. Specifically, the helper _try_copy in …
- CVE-2025-52566HIGHCVSS 8.6EG 8.62025-06-24
llama.cpp is an inference of several LLM models in C/C++. Prior to version b5721, there is a signed vs. unsigned integer overflow in llama.cpp's tokenizer implementation (llama_vocab::tokenize) (src/llama-vocab.cpp:3036) resulting in unint…
- CVE-2025-65495HIGHCVSS 7.5EG 7.52025-11-24
Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate that causes i2d_X509() to return -1 and be misused as a mallo…
- CVE-2025-67897MEDIUMCVSS 5.3EG 5.32025-12-14
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK pack…
- CVE-2026-41682MEDIUMCVSS 6.9EG 6.92026-05-08
pupnp is an SDK for development of UPnP device and control point applications. Prior to version 1.18.5, pupnp is vulnerable to SRRF port confusion due to port truncation via atoi() cast in parse_uri(). This issue has been patched in versio…
Map vulnerabilities like CWE-195 to your infrastructure
EchelonGraph correlates every CVE — across CWE-195 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →