Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-190

MITRE ↗

Integer Overflow or Wraparound

404
CRITICAL
1,945
HIGH
769
MEDIUM
87
LOW
3,248 CVEs · Page 26/65
7.8
CVE-2023-24949

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2023-2610

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.

7.8
CVE-2023-33204

sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists b

7.8
CVE-2023-2603

A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overf

7.8
CVE-2023-28295

Microsoft Publisher Remote Code Execution Vulnerability

7.8
CVE-2023-32434 KEV

An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11

7.8
CVE-2023-25004

A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploi

7.8
CVE-2023-32051

Raw Image Extension Remote Code Execution Vulnerability

7.8
CVE-2023-35312

Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability

7.8
CVE-2023-21241

In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer overflow. This could lea

7.8
CVE-2022-33065

Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header

7.8
CVE-2023-35372

Microsoft Office Visio Remote Code Execution Vulnerability

7.8
CVE-2023-36866

Microsoft Office Visio Remote Code Execution Vulnerability

7.8
CVE-2023-36900

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.8
CVE-2023-40022

Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.6.0 and prior are vulnerable to

7.8
CVE-2023-4734

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

7.8
CVE-2023-36792

Visual Studio Remote Code Execution Vulnerability

7.8
CVE-2023-38142

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2023-38150

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2023-43787

A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a lo

7.8
CVE-2023-36593

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

7.8
CVE-2023-46228

zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c,

7.8
CVE-2023-38127

An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted docum

7.8
CVE-2023-21375

In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to local escalation of

7.8
CVE-2023-4295

A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

7.8
CVE-2023-33018

Memory corruption while using the UIM diag command to get the operators name.

7.8
CVE-2023-48409

In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/mali_kbase_core_linux.c, there

7.8
CVE-2023-35632

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

7.8
CVE-2023-35644

Windows Sysmain Service Elevation of Privilege Vulnerability

7.7
CVE-2023-3487

An integer overflow in Silicon Labs Gecko Bootloader version 4.3.1 and earlier allows unbounded memory access when readi

7.6
CVE-2023-6478

A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can t

7.5
CVE-2023-22895

The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an int

7.5
CVE-2023-21557

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

7.5
CVE-2022-38725

An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a

7.5
CVE-2023-0705

Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who had one a race condition

7.5
CVE-2023-28097

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, a malformed SI

7.5
CVE-2023-25662

TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 are vulnerable to intege

7.5
CVE-2023-24537

Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can c

7.5
CVE-2023-30463

Altran picoTCP through 1.7.0 allows memory corruption (and subsequent denial of service) because of an integer overflow

7.5
CVE-2023-32058

Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, due to missing ove

7.5
CVE-2022-48480

Integer overflow vulnerability in some phones. Successful exploitation of this vulnerability may affect service confiden

7.5
CVE-2023-32307

Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-85

7.5
CVE-2020-20335

Buffer Overflow vulnerability in Antirez Kilo before commit 7709a04ae8520c5b04d261616098cebf742f5a23 allows a remote att

7.5
CVE-2023-21193

In VideoFrame of VideoFrame.h, there is a possible abort due to an integer overflow. This could lead to remote informati

7.5
CVE-2023-20689

In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service

7.5
CVE-2023-20690

In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service

7.5
CVE-2023-20691

In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service

7.5
CVE-2023-20693

In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of servi

7.5
CVE-2023-38403

iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.

7.5
CVE-2022-41409

Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecif

Frequently Asked Questions

What is CWE-190?

CWE-190 (Integer Overflow or Wraparound) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-190?

There are 3,987 CVE records associated with CWE-190 in our database. Of these, 404 are critical severity, 1945 are high severity, and 769 are medium severity.

How can I protect against CWE-190 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-190 using AI-powered security agents.

Detect CWE-190 Vulnerabilities

CyberStrike's AI agents automatically detect integer overflow or wraparound vulnerabilities across your infrastructure.

Get Started