Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-190

MITRE ↗

Integer Overflow or Wraparound

404
CRITICAL
1,945
HIGH
769
MEDIUM
87
LOW
3,248 CVEs · Page 21/65
7.5
CVE-2023-41185

Unified Automation UaGateway Certificate Parsing Integer Overflow Denial-of-Service Vulnerability. This vulnerability al

7.5
CVE-2023-49441

dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.

7.5
CVE-2023-33976

TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when no

7.5
CVE-2024-33024

Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the M

7.5
CVE-2024-45490

An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

7.5
CVE-2024-45287

A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a s

7.5
CVE-2023-45854

A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shoppin

7.5
CVE-2024-43566

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

7.5
CVE-2024-47739

In the Linux kernel, the following vulnerability has been resolved: padata: use integer wrap around to prevent deadlock

7.5
CVE-2024-42643

Integer Overflow in fast_ping.c in SmartDNS Release46 allows remote attackers to cause a Denial of Service via misaligne

7.5
CVE-2022-20685

A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker

7.5
CVE-2024-52912

Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offse

7.5
CVE-2024-42384

Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpect

7.5
CVE-2024-48983

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the len

7.5
CVE-2024-33063

Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside w

7.5
CVE-2024-53151

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Address an integer overflow Dan Carpenter

7.4
CVE-2023-40548

A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a

7.3
CVE-2024-27101

SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application per

7.3
CVE-2024-2212

In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (

7.3
CVE-2024-43495

Windows libarchive Remote Code Execution Vulnerability

7.2
CVE-2023-45742

An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3

7.2
CVE-2024-38019

Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability

7.2
CVE-2024-49089

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

7.1
CVE-2024-53111

In the Linux kernel, the following vulnerability has been resolved: mm/mremap: fix address wraparound in move_page_tabl

7.0
CVE-2023-32650

An integer overflow vulnerability exists in the FST_BL_GEOM parsing maxhandle functionality of GTKWave 3.3.115, when com

7.0
CVE-2023-35128

An integer overflow vulnerability exists in the fstReaderIterBlocks2 time_table tsec_nitems functionality of GTKWave 3.3

7.0
CVE-2023-35992

An integer overflow vulnerability exists in the FST fstReaderIterBlocks2 vesc allocation functionality of GTKWave 3.3.11

7.0
CVE-2023-38650

Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode times parsing functionality of GTKWav

7.0
CVE-2023-38651

Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode times parsing functionality of GTKWav

7.0
CVE-2023-38652

Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode dict parsing functionality of GTKWave

7.0
CVE-2023-38653

Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode dict parsing functionality of GTKWave

7.0
CVE-2024-2452

In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cau

6.8
CVE-2024-3077

An malicious BLE device can crash BLE victim device by sending malformed gatt packet

6.8
CVE-2024-29997

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

6.8
CVE-2024-29999

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

6.8
CVE-2024-30000

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

6.8
CVE-2024-30001

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

6.8
CVE-2024-30003

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

6.8
CVE-2024-30004

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

6.8
CVE-2024-30005

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

6.8
CVE-2024-30012

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

6.8
CVE-2024-30021

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

6.8
CVE-2024-26184

Secure Boot Security Feature Bypass Vulnerability

6.8
CVE-2024-49078

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

6.7
CVE-2023-33038

Memory corruption while receiving a message in Bus Socket Transport Server.

6.7
CVE-2024-20025

In da, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privil

6.7
CVE-2024-26171

Secure Boot Security Feature Bypass Vulnerability

6.7
CVE-2023-43545

Memory corruption when more scan frequency list or channels are sent from the user space.

6.7
CVE-2024-37976

Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability

6.7
CVE-2018-9404

In oemCallback of ril.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to lo

Frequently Asked Questions

What is CWE-190?

CWE-190 (Integer Overflow or Wraparound) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-190?

There are 3,987 CVE records associated with CWE-190 in our database. Of these, 404 are critical severity, 1945 are high severity, and 769 are medium severity.

How can I protect against CWE-190 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-190 using AI-powered security agents.

Detect CWE-190 Vulnerabilities

CyberStrike's AI agents automatically detect integer overflow or wraparound vulnerabilities across your infrastructure.

Get Started