CWE-190— Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.— MITRE CWE catalog
3,663 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-190page 1 of 74
- CVE-2013-2729CRITICALCVSS 9.8EG 9.8⚠ KEV2013-05-16
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.
- CVE-2016-1010CRITICALCVSS 8.8EG 9.8⚠ KEV2016-03-12
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compil…
- CVE-2023-6345CRITICALCVSS 9.6EG 9.6⚠ KEV2023-11-29
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
- CVE-2023-2136CRITICALCVSS 9.6EG 9.6⚠ KEV2023-04-19
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2021-30663CRITICALCVSS 8.8EG 9.0⚠ KEV2021-09-08
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbit…
- CVE-2018-6065CRITICALCVSS 8.8EG 9.0⚠ KEV2018-11-14
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2015-8651CRITICALCVSS 8.8EG 9.0⚠ KEV2015-12-28
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler b…
- CVE-2012-5054CRITICALCVSS 8.8EG 9.0⚠ KEV2012-09-24
Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.
- CVE-2025-48595CRITICALCVSS 8.4EG 9.0⚠ KEV2026-06-01
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…
- CVE-2023-33107CRITICALCVSS 8.4EG 9.0⚠ KEV2023-12-05
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
- CVE-2022-0185CRITICALCVSS 8.4EG 9.0⚠ KEV2022-02-11
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user names…
- CVE-2026-21385CRITICALCVSS 7.8EG 9.0⚠ KEV2026-03-02
Memory corruption while using alignments for memory allocation.
- CVE-2025-24985CRITICALCVSS 7.8EG 9.0⚠ KEV2025-03-11
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
- CVE-2024-38080CRITICALCVSS 7.8EG 9.0⚠ KEV2024-07-09
Windows Hyper-V Elevation of Privilege Vulnerability
- CVE-2023-32434CRITICALCVSS 7.8EG 9.0⚠ KEV2023-06-23
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 1…
- CVE-2023-21823CRITICALCVSS 7.8EG 9.0⚠ KEV2023-02-14
Windows Graphics Component Remote Code Execution Vulnerability
- CVE-2021-30952CRITICALCVSS 7.8EG 9.0⚠ KEV2021-08-24
An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary c…
- CVE-2021-30860CRITICALCVSS 7.8EG 9.0⚠ KEV2021-08-24
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbit…
- CVE-2018-14634CRITICALCVSS 7.8EG 9.0⚠ KEV2018-09-25
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel v…
- CVE-2013-2596CRITICALCVSS 7.8EG 9.0⚠ KEV2013-04-13
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the e…
- CVE-2011-1823CRITICALCVSS 7.8EG 9.0⚠ KEV2011-06-09
The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a…
- CVE-2026-4689CRITICALCVSS 10.0EG 10.02026-03-24
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
- CVE-2026-24814CRITICALCVSS 10.0EG 10.02026-01-27
Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is associated with program files sds.C. This issue affects swoole-src: before 6.0.2.
- CVE-2025-64721CRITICALCVSS 10.0EG 10.02025-12-11
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.6 and below, the SYSTEM-level service SbieSvc.exe exposes SbieIniServer::RC4Crypt to sandboxed processes. The handle…
- CVE-2013-2555HIGHCVSS v2 10.0EG 10.02013-03-11
Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on …
- CVE-2012-5143HIGHCVSS v2 10.0EG 10.02012-12-12
Integer overflow in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to PPAPI image buffers.
- CVE-2012-5835HIGHCVSS v2 10.0EG 10.02012-11-21
Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary c…
- CVE-2010-3254HIGHCVSS v2 10.0EG 10.02010-09-07
The WebSockets implementation in Google Chrome before 6.0.472.53 does not properly handle integer values, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
- CVE-2008-2663HIGHCVSS v2 10.0EG 10.02008-06-24
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial o…
- CVE-2026-93577CRITICALCVSS 9.9EG 9.92026-09-23
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on t…
- CVE-2020-27484CRITICALCVSS 9.9EG 9.92020-11-16
Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectIQ application to the ConnectIQ store. The…
- CVE-2026-88351CRITICALCVSS 9.8EG 9.82026-09-24
An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with an excessively large element count, the page allocation size calcu…
- CVE-2026-88365CRITICALCVSS 9.8EG 9.82026-09-24
minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-size field.
- CVE-2026-69586CRITICALCVSS 9.8EG 9.82026-09-08
Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
- CVE-2026-69408CRITICALCVSS 9.8EG 9.82026-09-08
Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- CVE-2026-85438CRITICALCVSS 9.8EG 9.82026-09-03
MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. Attackers ca…
- CVE-2026-84141CRITICALCVSS 9.8EG 9.82026-09-01
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- CVE-2025-70290CRITICALCVSS 9.8EG 9.82026-08-26
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-b…
- CVE-2025-70293CRITICALCVSS 9.8EG 9.82026-08-26
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() whic…
- CVE-2026-17160CRITICALCVSS 9.8EG 9.82026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.
- CVE-2026-16917CRITICALCVSS 9.8EG 9.82026-08-19
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow.
- CVE-2026-16834CRITICALCVSS 9.8EG 9.82026-08-19
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer underflow.
- CVE-2026-55191CRITICALCVSS 9.8EG 9.82026-08-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c with …
- CVE-2026-74964CRITICALCVSS 9.8EG 9.82026-08-18
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- CVE-2026-73193CRITICALCVSS 9.8EG 9.82026-08-15
DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. preparse reserves its output buffer with `newSV(strlen(statement) * 7 + 16)`, bud…
- CVE-2026-19001CRITICALCVSS 9.8EG 9.82026-08-12
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption …
- CVE-2026-43769CRITICALCVSS 9.8EG 9.82026-07-27
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watch…
- CVE-2026-43764CRITICALCVSS 9.8EG 9.82026-07-27
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
- CVE-2026-64694CRITICALCVSS 9.8EG 9.82026-07-27
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
- CVE-2026-64774CRITICALCVSS 9.8EG 9.82026-07-27
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A rem…
Map vulnerabilities like CWE-190 to your infrastructure
EchelonGraph correlates every CVE — across CWE-190 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →