In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supply
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_lo
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on th
A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for use
In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds read due to an integer overflow. This
In NDEF_MsgValidate of ndef_utils.c, there is a possible out of bounds read due to an integer overflow. This could lead
Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Intel(R) TXE versions be
In the camera, there is a possible out of bounds read due to an integer overflow. This could lead to local information d
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources
In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. A
An integer overflow was found in QEMU 4.0.1 through 4.2.0 in the way it implemented ATI VGA emulation. This flaw occurs
In IntensityCompare() of /MagickCore/quantize.c, a double value was being casted to int and returned, which in some case
WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outsid
In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ss
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by Ima
In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values ou
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by I
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by Ima
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by I
A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is processed by ImageMagick
There are 4 places in HistogramCompare() in MagickCore/histogram.c where an integer overflow is possible during simple m
In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, rounding calculations performed on unconst
A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who submits a crafted file that is processed
In IntensityCompare() of /magick/quantize.c, there are calls to PixelPacketIntensity() which could return overflowed val
A floating point math calculation in ScaleAnyToQuantum() of /MagickCore/quantum-private.h could lead to undefined behavi
A flaw was found in ImageMagick in coders/txt.c. An attacker who submits a crafted file that is processed by ImageMagick
libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in functio
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in f
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in t
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code
In Teeworlds 0.7.2, there is an integer overflow in CDataFileReader::Open() in engine/shared/datafile.cpp that can lead
In Teeworlds 0.7.2, there is an integer overflow in CMap::Load() in engine/shared/map.cpp that can lead to a buffer over
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (a
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-
In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. T
Unchecked OTA field in GNSS XTRA3 lead to integer overflow and then buffer overflow in Snapdragon Auto, Snapdragon Compu
Untrusted header fields in GNSS XTRA3 function can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snap
In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer o
Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in context of TEE
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Execution of code in TEE core (ke
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of
While storing calibrated data from firmware in cache, An integer overflow may occur since data length received may excee
Various Lexmark products have an Integer Overflow.
Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.
Frequently Asked Questions
What is CWE-190?
CWE-190 (Integer Overflow or Wraparound) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-190?
There are 3,987 CVE records associated with CWE-190 in our database. Of these, 404 are critical severity, 1945 are high severity, and 769 are medium severity.
How can I protect against CWE-190 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-190 using AI-powered security agents.
Detect CWE-190 Vulnerabilities
CyberStrike's AI agents automatically detect integer overflow or wraparound vulnerabilities across your infrastructure.
Get Started