FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi
LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (applicatio
A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote
Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially
Microsoft DirectMusic Information Disclosure Vulnerability
Integer overflow in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable de
Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp
Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update
snappy-java is a fast compressor/decompressor for Java. Due to unchecked multiplications, an integer overflow may occur
snappy-java is a fast compressor/decompressor for Java. Due to unchecked multiplications, an integer overflow may occur
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an i
Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT
Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` comm
Integer overflow vulnerability in function Q_DecCoordOnUnitSphere file bifs/unquantize.c in GPAC version 2.2-rev0-gab012
A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test c
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
A vulnerability was found in SerenityOS. It has been rated as critical. Affected by this issue is the function initializ
Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SRANDMEMBER`, `ZRAN
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.
Windows iSCSI Target Service Information Disclosure Vulnerability
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size
An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local
Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attac
Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local
Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.3-DEV.
Windows Kernel Information Disclosure Vulnerability
An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSp
An integer overflow flaw was found in the Linux kernel. This issue leads to the kernel allocating `skb_shared_info` in t
Windows DNS Server Information Disclosure Vulnerability
Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. Accor
Integer overflow in the Intel(R) Trace Analyzer and Collector software before version 2021.5 may allow an authenticated
In wlan, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclos
In soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial
Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_g
Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties
Vim is an open source command line text editor. If the count after the :s command is larger than what fits into a (signe
Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for
Vim is an open source command line text editor. When parsing relative ex addresses one may unintentionally cause an over
Vim is an open source command line text editor. When using the z= command, the user may overflow the count with values l
Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and us
An issue was discovered in Exynos Mobile Processor 980 and 2100. An integer overflow at a buffer index can prevent the e
An issue was discovered in the NPU kernel driver in Samsung Exynos Mobile Processor 9820, 980, 2100, 2200, 1280, and 138
There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may c
Frequently Asked Questions
What is CWE-190?
CWE-190 (Integer Overflow or Wraparound) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-190?
There are 3,987 CVE records associated with CWE-190 in our database. Of these, 404 are critical severity, 1945 are high severity, and 769 are medium severity.
How can I protect against CWE-190 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-190 using AI-powered security agents.
Detect CWE-190 Vulnerabilities
CyberStrike's AI agents automatically detect integer overflow or wraparound vulnerabilities across your infrastructure.
Get Started