CWE-190— Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.— MITRE CWE catalog
3,340 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-190page 64 of 67
- CVE-2026-4150HIGHCVSS 7.8EG 7.82026-04-11
GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability …
- CVE-2026-4151HIGHCVSS 7.8EG 7.82026-04-11
GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability …
- CVE-2026-41521CRITICALCVSS 9.1EG 9.12026-07-20
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensio…
- CVE-2026-4154HIGHCVSS 7.8EG 7.82026-04-11
GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability …
- CVE-2026-41602HIGHCVSS 7.5EG 7.52026-04-28
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
- CVE-2026-41605HIGHCVSS 7.3EG 7.32026-04-28
Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
- CVE-2026-41664MEDIUMCVSS 6.6EG 6.62026-04-22
Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes. Affected version is prior to commit 1.30.0.
- CVE-2026-41665MEDIUMCVSS 6.1EG 6.12026-04-22
Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for large intermediate tensors. Affected version is prior to commit 1.30.0.
- CVE-2026-41666MEDIUMCVSS 6.6EG 6.62026-04-22
Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during loop state propagation. Affected version is prior to commit 1.30.0.
- CVE-2026-41667MEDIUMCVSS 6.6EG 6.62026-04-22
Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes. Affected version is prior to commit 1.30.0.
- CVE-2026-41849HIGHCVSS 7.5EG 7.52026-06-09
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resultin…
- CVE-2026-41977MEDIUMCVSS 5.0EG 5.02026-06-09
DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-42046HIGHCVSS 7.8EG 7.82026-05-11
libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-bounds write (heap overflow) by supplying a …
- CVE-2026-42144MEDIUMCVSS 6.1EG 6.12026-05-04
CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted PNM/PGM/PPM fil…
- CVE-2026-42199MEDIUMCVSS 6.2EG 6.22026-05-08
Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand_rows() can corrupt the relationship between the grid’s logical dimensions and its backing storage. After the interna…
- CVE-2026-42217CRITICALCVSS 9.8EG 9.82026-05-07
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readV…
- CVE-2026-42308MEDIUMCVSS 5.5EG 5.52026-05-09
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched i…
- CVE-2026-42311HIGHCVSS 7.8EG 7.82026-05-09
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in…
- CVE-2026-42580MEDIUMCVSS 6.5EG 6.52026-05-13
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Fina…
- CVE-2026-42627MEDIUMCVSS 6.2EG 6.22026-05-26
In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to bypass buffer size validation and trigger a heap-based buffer over-read during model optimizati…
- CVE-2026-42798MEDIUMCVSS 4.0EG 4.02026-04-30
Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.
- CVE-2026-42896HIGHCVSS 7.8EG 7.82026-05-12
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- CVE-2026-42916HIGHCVSS 7.8EG 7.82026-06-09
Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-42974HIGHCVSS 8.1EG 8.12026-06-09
Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.
- CVE-2026-43254HIGHCVSS 7.5EG 7.52026-05-06
In the Linux kernel, the following vulnerability has been resolved: ovpn: tcp - fix packet extraction from stream When processing TCP stream data in ovpn_tcp_recv, we receive large cloned skbs from __strp_rcv that may contain multiple co…
- CVE-2026-43492MEDIUMCVSS 5.5EG 5.52026-05-19
In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming reports an integer underflow in mpi_read_raw_from_sgl() when subtracting "lzeros" from the unsig…
- CVE-2026-43618HIGHCVSS 8.1EG 8.12026-05-20
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver…
- CVE-2026-43764CRITICALCVSS 9.8EG 9.82026-07-27
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
- CVE-2026-43769CRITICALCVSS 9.8EG 9.82026-07-27
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to c…
- CVE-2026-43780HIGHCVSS 7.8EG 7.82026-07-27
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciousl…
- CVE-2026-43818HIGHCVSS 8.8EG 8.82026-07-27
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary co…
- CVE-2026-43894MEDIUMCVSS 6.2EG 6.22026-05-11
jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the…
- CVE-2026-43905HIGHCVSS 7.8EG 7.82026-05-14
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, jpeg2000input.cpp:395 computes buffer size as const int bufsize = w * h * ch …
- CVE-2026-43907HIGHCVSS 8.3EG 8.32026-05-14
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed integer overflow in QueryRGBBufferSizeInternal() in DPXColorConverte…
- CVE-2026-43908HIGHCVSS 8.8EG 8.82026-05-14
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the pixel-loop index expression i * 3 ins…
- CVE-2026-43909HIGHCVSS 8.8EG 8.82026-05-14
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the loop index expression i * 4 inside Sw…
- CVE-2026-44216HIGHCVSS 7.5EG 7.52026-05-14
Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained checked arithmetic which panicked on overflow. This overflow is possible to trigger, and thus p…
- CVE-2026-4452HIGHCVSS 8.8EG 8.82026-03-20
Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-4453MEDIUMCVSS 4.3EG 4.32026-03-20
Integer overflow in Dawn in Google Chrome on Mac prior to 146.0.7680.153 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-44636HIGHCVSS 7.4EG 7.42026-05-14
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The public sixel_encode e…
- CVE-2026-44637HIGHCVSS 7.1EG 7.12026-05-14
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's image-buffer doubling loop can lead to an out-of-bounds heap write in sixel_decode_raw_impl. …
- CVE-2026-4464HIGHCVSS 8.8EG 8.82026-03-20
Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-44663HIGHCVSS 7.1EG 7.12026-06-18
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, an integer overflow in ht_undo_impl() in src/lib/OpenEXRCore/internal_ht.cpp …
- CVE-2026-44673HIGHCVSS 7.5EG 7.52026-05-14
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker…
- CVE-2026-44803HIGHCVSS 7.8EG 7.82026-06-09
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
- CVE-2026-44812HIGHCVSS 7.8EG 7.82026-06-09
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
- CVE-2026-44983HIGHCVSS 7.3EG 7.32026-05-26
smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an undersized heap allocation, resulting in a heap buffer overflow …
- CVE-2026-45130MEDIUMCVSS 5.5EG 5.52026-05-08
Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (.spl) with UTF-8 encoding active. An attacker-controlled len…
- CVE-2026-45258HIGHCVSS 7.8EG 7.82026-06-27
dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition could overflow, so that a large offset and length wrapped around and passed the check. Th…
- CVE-2026-45592HIGHCVSS 7.8EG 7.82026-06-09
Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-190 to your infrastructure
EchelonGraph correlates every CVE — across CWE-190 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →