Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-190

MITRE ↗

Integer Overflow or Wraparound

404
CRITICAL
1,945
HIGH
769
MEDIUM
87
LOW
3,248 CVEs · Page 28/65
6.5
CVE-2023-40186

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi

6.5
CVE-2023-40745

LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (applicatio

6.5
CVE-2023-41175

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote

6.5
CVE-2023-22305

Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially

6.2
CVE-2023-35341

Microsoft DirectMusic Information Disclosure Vulnerability

6.0
CVE-2023-22443

Integer overflow in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable de

5.9
CVE-2022-33266

Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp

5.9
CVE-2022-33296

Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update

5.9
CVE-2023-34453

snappy-java is a fast compressor/decompressor for Java. Due to unchecked multiplications, an integer overflow may occur

5.9
CVE-2023-34454

snappy-java is a fast compressor/decompressor for Java. Due to unchecked multiplications, an integer overflow may occur

5.5
CVE-2022-44425

In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-44426

In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-44432

In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

5.5
CVE-2021-26346

Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an i

5.5
CVE-2022-35977

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT

5.5
CVE-2023-22458

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` comm

5.5
CVE-2023-23144

Integer overflow vulnerability in function Q_DecCoordOnUnitSphere file bifs/unquantize.c in GPAC version 2.2-rev0-gab012

5.5
CVE-2023-0615

A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test c

5.5
CVE-2022-38674

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-38680

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-47322

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-47451

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

5.5
CVE-2021-4327

A vulnerability was found in SerenityOS. It has been rated as critical. Affected by this issue is the function initializ

5.5
CVE-2023-25155

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SRANDMEMBER`, `ZRAN

5.5
CVE-2022-47454

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

5.5
CVE-2022-48468

protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.

5.5
CVE-2023-24945

Windows iSCSI Target Service Information Disclosure Vulnerability

5.5
CVE-2023-34151

A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size

5.5
CVE-2023-38560

An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local

5.5
CVE-2021-28025

Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attac

5.5
CVE-2021-28429

Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local

5.5
CVE-2023-4722

Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.3-DEV.

5.5
CVE-2023-36576

Windows Kernel Information Disclosure Vulnerability

5.5
CVE-2023-42298

An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSp

5.5
CVE-2023-42752

An integer overflow flaw was found in the Linux kernel. This issue leads to the kernel allocating `skb_shared_info` in t

4.9
CVE-2023-28277

Windows DNS Server Information Disclosure Vulnerability

4.9
CVE-2023-38698

Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. Accor

4.8
CVE-2022-34843

Integer overflow in the Intel(R) Trace Analyzer and Collector software before version 2021.5 may allow an authenticated

4.4
CVE-2023-20660

In wlan, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclos

4.4
CVE-2022-47489

In soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial

4.0
CVE-2023-46246

Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_g

3.3
CVE-2020-19909

Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties

2.8
CVE-2023-48233

Vim is an open source command line text editor. If the count after the :s command is larger than what fits into a (signe

2.8
CVE-2023-48234

Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for

2.8
CVE-2023-48235

Vim is an open source command line text editor. When parsing relative ex addresses one may unintentionally cause an over

2.8
CVE-2023-48236

Vim is an open source command line text editor. When using the z= command, the user may overflow the count with values l

2.8
CVE-2023-48237

Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and us

2.0
CVE-2023-40353

An issue was discovered in Exynos Mobile Processor 980 and 2100. An integer overflow at a buffer index can prevent the e

2.0
CVE-2023-40218

An issue was discovered in the NPU kernel driver in Samsung Exynos Mobile Processor 9820, 980, 2100, 2200, 1280, and 138

9.8
CVE-2021-39993

There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may c

Frequently Asked Questions

What is CWE-190?

CWE-190 (Integer Overflow or Wraparound) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-190?

There are 3,987 CVE records associated with CWE-190 in our database. Of these, 404 are critical severity, 1945 are high severity, and 769 are medium severity.

How can I protect against CWE-190 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-190 using AI-powered security agents.

Detect CWE-190 Vulnerabilities

CyberStrike's AI agents automatically detect integer overflow or wraparound vulnerabilities across your infrastructure.

Get Started