CWE-190— Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.— MITRE CWE catalog
3,331 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-190page 48 of 67
- CVE-2023-36864HIGHCVSS 7.8EG 7.82024-01-08
An integer overflow vulnerability exists in the fstReaderIterBlocks2 temp_signal_value_buf allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malic…
- CVE-2023-36866HIGHCVSS 7.8EG 7.82023-08-08
Microsoft Office Visio Remote Code Execution Vulnerability
- CVE-2023-36900HIGHCVSS 7.8EG 7.82023-08-08
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2023-36910CRITICALCVSS 9.8EG 9.82023-08-08
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36911CRITICALCVSS 9.8EG 9.82023-08-08
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36915HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a mali…
- CVE-2023-36916HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a mali…
- CVE-2023-37327HIGHCVSS 8.8EG 8.82024-05-03
GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exp…
- CVE-2023-37536HIGHCVSS 8.2EG 8.22023-10-11
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
- CVE-2023-38103HIGHCVSS 8.8EG 8.82024-05-03
GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required t…
- CVE-2023-38104HIGHCVSS 8.8EG 8.82024-05-03
GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required t…
- CVE-2023-38127HIGHCVSS 7.8EG 7.82023-10-19
An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially re…
- CVE-2023-38142HIGHCVSS 7.8EG 7.82023-09-12
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-38150HIGHCVSS 7.8EG 7.82023-09-12
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-38403HIGHCVSS 7.5EG 7.52023-07-17
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
- CVE-2023-38560MEDIUMCVSS 5.5EG 5.52023-08-01
An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.
- CVE-2023-38618HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger th…
- CVE-2023-38619HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger th…
- CVE-2023-38620HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger th…
- CVE-2023-38621HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger th…
- CVE-2023-38622HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger th…
- CVE-2023-38623HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger th…
- CVE-2023-38650HIGHCVSS 7.0EG 7.02024-01-08
Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode times parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to memory corruption. A victim would need to open a malicious file to…
- CVE-2023-38651HIGHCVSS 7.0EG 7.02024-01-08
Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode times parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to memory corruption. A victim would need to open a malicious file to…
- CVE-2023-38652HIGHCVSS 7.0EG 7.02024-01-08
Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode dict parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to memory corruption. A victim would need to open a malicious file to …
- CVE-2023-38653HIGHCVSS 7.0EG 7.02024-01-08
Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode dict parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to memory corruption. A victim would need to open a malicious file to …
- CVE-2023-38698MEDIUMCVSS 4.9EG 4.92023-08-04
Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. According to the documentation, controllers are allowed to register new domains and extend the expiry of existing domains, b…
- CVE-2023-39125HIGHCVSS 7.5EG 7.52023-08-18
NTSC-CRT 2.2.1 has an integer overflow and out-of-bounds write in loadBMP in bmp_rw.c because a file's width, height, and BPP are not validated. NOTE: the vendor's perspective is "this main application was not intended to be a well tested …
- CVE-2023-39270HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger …
- CVE-2023-39271HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger …
- CVE-2023-39272HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger …
- CVE-2023-39273HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger …
- CVE-2023-39274HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger …
- CVE-2023-39275HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger …
- CVE-2023-39316HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger the…
- CVE-2023-39317HIGHCVSS 7.8EG 7.82024-01-08
Multiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger the…
- CVE-2023-40022HIGHCVSS 7.8EG 7.82023-08-24
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.6.0 and prior are vulnerable to integer overflow in `consume_count` of `src/gnu_v2/cplus-dem.c`. The overflow check is valid logic but, is missing the …
- CVE-2023-40186MEDIUMCVSS 6.5EG 6.52023-08-31
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an IntegerOverflow leading to Out-Of-Bound Write Vulnerability in the `gdi_CreateSurface` function. …
- CVE-2023-40218LOWCVSS 2.0EG 2.02023-09-12
An issue was discovered in the NPU kernel driver in Samsung Exynos Mobile Processor 9820, 980, 2100, 2200, 1280, and 1380. An integer overflow can bypass detection of error cases via a crafted application.
- CVE-2023-40353LOWCVSS 2.0EG 2.02023-09-08
An issue was discovered in Exynos Mobile Processor 980 and 2100. An integer overflow at a buffer index can prevent the execution of requested services via a crafted application.
- CVE-2023-40474HIGHCVSS 8.8EG 8.82024-05-03
GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to expl…
- CVE-2023-40475HIGHCVSS 8.8EG 8.82024-05-03
GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to expl…
- CVE-2023-40548HIGHCVSS 7.4EG 7.42024-01-29
A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation op…
- CVE-2023-40745MEDIUMCVSS 6.5EG 6.52023-10-05
LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.
- CVE-2023-41056HIGHCVSS 8.1EG 8.12024-01-10
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in…
- CVE-2023-41175MEDIUMCVSS 6.5EG 6.52023-10-05
A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a…
- CVE-2023-41185HIGHCVSS 7.5EG 8.62024-05-03
Unified Automation UaGateway Certificate Parsing Integer Overflow Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway…
- CVE-2023-42295HIGHCVSS 8.8EG 8.82023-10-23
An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_rle_image function of file bifs/unquantize.c
- CVE-2023-42298MEDIUMCVSS 5.5EG 5.52023-10-12
An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSphere function of file src/bifs/unquantize.c.
- CVE-2023-42562HIGHCVSS 7.8EG 7.82023-12-05
Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
Map vulnerabilities like CWE-190 to your infrastructure
EchelonGraph correlates every CVE — across CWE-190 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →