Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-190

MITRE ↗

Integer Overflow or Wraparound

404
CRITICAL
1,945
HIGH
769
MEDIUM
87
LOW
3,248 CVEs · Page 5/65
7.8
CVE-2026-50435

Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-54115

Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-54124

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55033

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55043

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55048

Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-56182

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-58532

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-48342

Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in t

7.8
CVE-2026-33327

libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and includ

7.8
CVE-2026-16554

cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. Th

7.8
CVE-2026-66758

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory alloca

7.8
CVE-2026-43780

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS

7.8
CVE-2026-64765

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10,

7.8
CVE-2026-64766

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10,

7.8
CVE-2026-21366

Memory corruption while processing a packet with a size close to the maximum allowed value.

7.8
CVE-2026-71261

dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. I

7.8
CVE-2026-43627

llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where

7.8
CVE-2026-70628

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtit

7.8
CVE-2026-70638

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where th

7.8
CVE-2026-58641

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

7.8
CVE-2026-59127

Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-61937

Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62735

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62751

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges loca

7.8
CVE-2026-62886

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

7.8
CVE-2026-63532

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-64898

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-64903

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-64911

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-65814

Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-47940

Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code exe

7.8
CVE-2026-18917

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFr

7.8
CVE-2026-18300

GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t

7.8
CVE-2026-18301

GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t

7.8
CVE-2026-18304

GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t

7.8
CVE-2026-18305

GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t

7.8
CVE-2026-18306

GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t

7.8
CVE-2026-18308

GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t

7.8
CVE-2026-18309

GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers

7.8
CVE-2026-72852

hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken f

7.8
CVE-2026-52492

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result

7.7
CVE-2026-58207

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.

7.6
CVE-2026-11774

An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(

7.6
CVE-2026-53705

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack f

7.6
CVE-2026-6682

In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap,

7.5
CVE-2026-23833

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In versions 2025.9.0 through 2

7.5
CVE-2026-25989

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1

7.5
CVE-2026-30910

Crypt::Sodium::XS versions through 0.001000 for Perl has potential integer overflows. Combined aead encryption, combine

7.5
CVE-2026-31814

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a special

Frequently Asked Questions

What is CWE-190?

CWE-190 (Integer Overflow or Wraparound) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-190?

There are 3,987 CVE records associated with CWE-190 in our database. Of these, 404 are critical severity, 1945 are high severity, and 769 are medium severity.

How can I protect against CWE-190 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-190 using AI-powered security agents.

Detect CWE-190 Vulnerabilities

CyberStrike's AI agents automatically detect integer overflow or wraparound vulnerabilities across your infrastructure.

Get Started