There is a software integer overflow leading to a TOCTOU condition in smartphones. Successful exploitation of this vulne
Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Inte
Integer overflow vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows l
In ccu driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of
In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an integer overflow. This c
In prepare_io_entry and prepare_response of lwis_ioctl.c and lwis_periodic_io.c, there is a possible out of bounds write
In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi
In ioctl_dpm_qos_update and ioctl_event_control_set of (TBD), there is a possible out of bounds write due to an integer
In ioctl_dpm_clk_update of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could
In construct_transaction of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could
In teei, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privil
In audio ipi, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of
In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local e
In preloader (usb), there is a possible out of bounds write due to an integer overflow. This could lead to local escalat
An internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. Th
Tensorflow is an Open Source Machine Learning Framework. The implementations of `Sparse*Cwise*` ops are vulnerable to in
Tensorflow is an Open Source Machine Learning Framework. The implementation of `AddManySparseToTensorsMap` is vulnerable
Tensorflow is an Open Source Machine Learning Framework. The implementation of `UnravelIndex` is vulnerable to a divisio
Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` can be made to
Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateTensorSiz
Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateOutputSiz
stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This v
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for i
Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCr
In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eve
A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.
Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2
Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.2.
GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header.
In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible
An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of
Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vu
A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted fil
An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the co
An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0.
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i80
yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` co
TensorFlow is an open source platform for machine learning. The `RaggedRangOp` function takes an argument `limits` that
TensorFlow is an open source platform for machine learning. When `RangeSize` receives values that do not fit into an `in
Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component.
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient val
Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2
MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.
Some Huawei products have an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to k
An integer overflow in DTSStreamReader::findFrame() of tsMuxer git-2678966 allows attackers to cause a Denial of Service
A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who
A flaw was found in the Linux kernel. A denial of service problem is identified if an extent tree is corrupted in a craf
The microweber application allows large characters to insert in the input field "post title" which can allow attackers t
The microweber application allows large characters to insert in the input field "fist & last name" which can allow attac
An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could caus
Frequently Asked Questions
What is CWE-190?
CWE-190 (Integer Overflow or Wraparound) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-190?
There are 3,987 CVE records associated with CWE-190 in our database. Of these, 404 are critical severity, 1945 are high severity, and 769 are medium severity.
How can I protect against CWE-190 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-190 using AI-powered security agents.
Detect CWE-190 Vulnerabilities
CyberStrike's AI agents automatically detect integer overflow or wraparound vulnerabilities across your infrastructure.
Get Started