Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet
An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h contains multip
u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value a
u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are
u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can l
u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size result
u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential in
u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon
u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Sn
u'A potential buffer overflow exists due to integer overflow when parsing handler options due to wrong data type usage i
An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged atta
An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13
An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.1
In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to
In Mediaserver, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation
In libavb, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of pr
In remove of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local
An integer overflow was addressed through improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, ma
In create of FileMap.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local e
u'Integer overflow can cause a buffer overflow due to lack of table length check in the extensible boot Loader during th
u'Possible buffer overflow in WMA message processing due to integer overflow occurs when processing command received fro
u'Possible integer overflow to heap overflow while processing command due to lack of check of packet length received' in
Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow a
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by I
An integer overflow was addressed through improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchO
In SPDIFEncoder::writeBurstBufferBytes and related methods of SPDIFEncoder.cpp, there is a possible out of bounds write
GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entri
In NFA_RwI93WriteMultipleBlocks of nfa_rw_api.cc, there is a possible out of bounds write due to an integer overflow. Th
The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' byte
An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalid
There is an integer overflow vulnerability in LDAP client of some Huawei products. Due to insufficient input validation,
There is an integer overflow vulnerability in LDAP server of some Huawei products. Due to insufficient input validation,
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660
An exploitable denial-of-service vulnerability exists in the TXT record-parsing functionality of Videolabs libmicrodns 0
An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. There is an Integer Overflow in proce
On High-End SRX Series devices, in specific configurations and when specific networking events or operator actions occur
A malicious userspace application can cause a integer overflow and bypass security checks performed by system call handl
In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow. This could lead to
In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This
In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could le
Memory leaks were discovered in the CoAP library in Arm Mbed OS 5.15.3 when using the Arm mbed-coap library 5.1.5. The C
An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could resu
In Parse_wave of eas_mdls.c, there is a possible out of bounds write due to an integer overflow. This could lead to remo
An integer overflow was discovered in YGOPro ygocore v13.51. Attackers can use it to leak the game server thread's memor
An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An att
An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack compone
An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsin
An issue was discovered in picoTCP 1.7.0. The code for parsing the hop-by-hop IPv6 extension headers does not validate t
An issue was discovered in picoTCP 1.7.0. The code for creating an ICMPv6 echo replies doesn't check whether the ICMPv6
Frequently Asked Questions
What is CWE-190?
CWE-190 (Integer Overflow or Wraparound) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-190?
There are 3,987 CVE records associated with CWE-190 in our database. Of these, 404 are critical severity, 1945 are high severity, and 769 are medium severity.
How can I protect against CWE-190 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-190 using AI-powered security agents.
Detect CWE-190 Vulnerabilities
CyberStrike's AI agents automatically detect integer overflow or wraparound vulnerabilities across your infrastructure.
Get Started