CWE-190— Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.— MITRE CWE catalog
3,331 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-190page 55 of 67
- CVE-2024-6638MEDIUMCVSS 5.5EG 5.52024-07-22
An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an infinite loop. Successful exploitation requires an attacker to provide a user with a specially crafted TDMS file. This…
- CVE-2024-7025HIGHCVSS 8.8EG 8.82024-11-27
Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-7488MEDIUMCVSS 5.3EG 5.32024-12-04
Integer Overflow or Wraparound, Improper Validation of Specified Quantity in Input vulnerability in RestApp Inc. Online Ordering System allows Integer Attacks. This issue affects Online Ordering System: 8.2.1. NOTE: Vulnerability…
- CVE-2024-7867MEDIUMCVSS 6.2EG 6.22024-08-15
In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.
- CVE-2024-9123HIGHCVSS 8.8EG 8.82024-09-25
Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-0005HIGHCVSS 7.3EG 7.32025-11-24
Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resulting in crash or denial of service.
- CVE-2025-0101MEDIUMCVSS 6.5EG 6.52025-04-16
A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes some functions to work unexpected or stop working at all. Both during runtime and after a restart.
- CVE-2025-0302MEDIUMCVSS 5.5EG 5.52025-02-07
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through integer overflow.
- CVE-2025-0587LOWCVSS 3.8EG 3.82025-03-04
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. This vulnerability can be exploited only in restricted scenarios.
- CVE-2025-0678HIGHCVSS 7.8EG 7.82025-03-03
A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for integer …
- CVE-2025-0838CRITICALCVSS 9.8EG 9.82025-02-21
There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on their size argument. As a result, it was possible for …
- CVE-2025-10456HIGHCVSS 7.1EG 7.12025-09-19
A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a flaw that causes the BLE target (i.e., the device under attack) to attempt to disco…
- CVE-2025-10533HIGHCVSS 8.8EG 8.82025-09-16
Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
- CVE-2025-10892HIGHCVSS 8.8EG 8.82025-09-24
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-10923HIGHCVSS 7.8EG 7.82025-10-29
GIMP WBMP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability…
- CVE-2025-10924HIGHCVSS 7.8EG 7.82025-10-29
GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability i…
- CVE-2025-11152HIGHCVSS 8.6EG 8.62025-09-30
Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.0.3.
- CVE-2025-11463HIGHCVSS 7.8EG 7.82025-10-29
Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required…
- CVE-2025-12035MEDIUMCVSS 6.5EG 6.52025-12-15
An integer overflow condition exists in Bluetooth Host stack, within the bt_br_acl_recv routine a critical path for processing inbound BR/EDR L2CAP traffic.
- CVE-2025-1235MEDIUMCVSS 4.3EG 4.32025-06-02
A low privileged attacker can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes the date of the switch to be set back to January 1st, 1970.
- CVE-2025-12501HIGHCVSS 7.5EG 7.52025-10-31
Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-service attacks (DoS). GameMaker users who use the network_create_server() function in their projects are urged to up…
- CVE-2025-12818MEDIUMCVSS 5.9EG 5.92025-11-13
Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a se…
- CVE-2025-13601HIGHCVSS 7.7EG 7.72025-11-26
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need…
- CVE-2025-14087CRITICALCVSS 9.8EG 9.82025-12-10
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciousl…
- CVE-2025-14098HIGHCVSS 7.8EG 7.82026-06-12
Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This …
- CVE-2025-14178MEDIUMCVSS 6.5EG 6.52025-12-27
In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or H…
- CVE-2025-14242MEDIUMCVSS 6.5EG 6.52026-01-14
A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte …
- CVE-2025-14299MEDIUMCVSS 6.5EG 6.52025-12-20
The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessiv…
- CVE-2025-14308CRITICALCVSS 9.8EG 9.82025-12-09
An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially lead…
- CVE-2025-14422HIGHCVSS 7.8EG 7.82025-12-23
GIMP PNM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability …
- CVE-2025-14512MEDIUMCVSS 6.5EG 6.52025-12-11
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesys…
- CVE-2025-14933HIGHCVSS 7.8EG 7.82025-12-23
NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NSF Unidata NetCDF-C. User interaction is required to …
- CVE-2025-15278HIGHCVSS 7.8EG 7.82025-12-31
FontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit th…
- CVE-2025-15534MEDIUMCVSS 7.8EG 5.32026-01-18
A vulnerability was identified in raysan5 raylib up to 909f040. Affected by this issue is the function LoadFontData of the file src/rtext.c. The manipulation leads to integer overflow. The attack can only be performed from a local environm…
- CVE-2025-15584MEDIUMCVSS 6.8EG 6.82026-03-17
Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an integer overflow within the filt…
- CVE-2025-20024LOWCVSS 3.8EG 3.82025-03-04
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. This vulnerability can be exploited only in restricted scenarios.
- CVE-2025-2021HIGHCVSS 7.8EG 7.82025-03-11
Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required…
- CVE-2025-2023HIGHCVSS 7.8EG 7.82025-03-11
Ashlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required…
- CVE-2025-20653MEDIUMCVSS 6.5EG 6.52025-03-03
In da, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction i…
- CVE-2025-20710HIGHCVSS 8.8EG 8.82025-10-14
In wlan AP driver, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- CVE-2025-20722MEDIUMCVSS 5.5EG 5.52025-10-14
In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitat…
- CVE-2025-20803MEDIUMCVSS 6.7EG 6.72026-01-06
In dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch I…
- CVE-2025-20807MEDIUMCVSS 6.7EG 6.72026-01-06
In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. P…
- CVE-2025-2082HIGHCVSS 7.5EG 7.52025-04-30
Tesla Model 3 VCSEC Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. Authentication is not required to exploit this vul…
- CVE-2025-21172HIGHCVSS 7.5EG 7.52025-01-14
.NET and Visual Studio Remote Code Execution Vulnerability
- CVE-2025-21243HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21244HIGHCVSS 8.8EG 8.82025-01-14
Windows Telephony Service Remote Code Execution Vulnerability
- CVE-2025-21338HIGHCVSS 7.8EG 7.82025-01-14
GDI+ Remote Code Execution Vulnerability
- CVE-2025-21369HIGHCVSS 8.8EG 8.82025-02-11
Microsoft Digest Authentication Remote Code Execution Vulnerability
- CVE-2025-21382HIGHCVSS 7.8EG 7.82025-01-14
Windows Graphics Component Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-190 to your infrastructure
EchelonGraph correlates every CVE — across CWE-190 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →