CWE-682— Incorrect Calculation
The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.— MITRE CWE catalog
136 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-682page 2 of 3
- CVE-2021-3004HIGHCVSS 7.5EG 7.52021-01-03
The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should.
- CVE-2021-3114MEDIUMCVSS 6.5EG 6.52021-01-26
In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.
- CVE-2021-31440HIGHCVSS 7.0EG 7.02021-05-21
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vuln…
- CVE-2021-34573MEDIUMCVSS 6.2EG 6.22021-09-16
In Enbra EWM in Version 1.7.29 together with several tested wireless M-Bus Sensors the events backflow and "no flow" are not reconized or misinterpreted. This may lead to wrong values and missing events.
- CVE-2021-41122MEDIUMCVSS 4.3EG 4.32021-10-05
Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions external functions did not properly validate the bounds of decimal arguments. The can lead to logic errors. This issue has been resolved in version 0.3.0.
- CVE-2021-41222MEDIUMCVSS 5.5EG 5.52021-11-05
TensorFlow is an open source platform for machine learning. In affected versions the implementation of `SplitV` can trigger a segfault is an attacker supplies negative arguments. This occurs whenever `size_splits` contains more than one va…
- CVE-2021-41329MEDIUMCVSS 6.5EG 6.52021-09-27
Datalust Seq before 2021.2.6259 allows users (with view filters applied to their accounts) to see query results not constrained by their view filter. This information exposure, caused by an internal cache key collision, occurs when the use…
- CVE-2021-44490HIGHCVSS 7.5EG 7.52022-04-15
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a …
- CVE-2021-44491HIGHCVSS 7.5EG 7.52022-04-15
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a …
- CVE-2021-44504HIGHCVSS 7.5EG 7.52022-04-15
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a size variable, stored as an signed int, to equal an extremely large value, which is interpreted as a nega…
- CVE-2021-44847CRITICALCVSS 9.8EG 9.82021-12-13
A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers t…
- CVE-2021-45960HIGHCVSS 8.8EG 8.82022-01-01
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
- CVE-2022-22138HIGHCVSS 7.5EG 7.52022-06-17
All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault…
- CVE-2022-23001MEDIUMCVSS 5.3EG 5.32022-07-29
When compressing or decompressing elliptic curve points using the Sweet B library, an incorrect choice of sign bit is used. An attacker with user level privileges and no other user's assistance can exploit this vulnerability with only know…
- CVE-2022-23003MEDIUMCVSS 5.3EG 5.32022-07-29
When computing a shared secret or point multiplication on the NIST P-256 curve that results in an X coordinate of zero, the resulting output is not properly reduced modulo the P-256 field prime and is invalid. The resulting output may caus…
- CVE-2022-23004MEDIUMCVSS 5.3EG 5.32022-07-29
When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate of zero, an error is returned from the library, and an invalid unreduced value is written to the output buffer. This may…
- CVE-2022-23011HIGHCVSS 7.5EG 7.52022-01-25
On certain hardware BIG-IP platforms, in version 15.1.x before 15.1.4 and 14.1.x before 14.1.3, virtual servers may stop responding while processing TCP traffic due to an issue in the SYN Cookie Protection feature. Note: Software versions …
- CVE-2022-23028MEDIUMCVSS 5.3EG 5.32022-01-25
On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when global AFM SYN cookie protection (TCP Half Open flood vector) is activated in the AFM Device Dos or DOS profile, certa…
- CVE-2022-23066CRITICALCVSS 9.1EG 9.12022-05-09
In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For exampl…
- CVE-2022-23628MEDIUMCVSS 6.3EG 6.32022-02-09
OPA is an open source, general-purpose policy engine. Under certain conditions, pretty-printing an abstract syntax tree (AST) that contains synthetic nodes could change the logic of some statements by reordering array literals. Example of …
- CVE-2022-26517HIGHCVSS 5.9EG 7.52022-05-05
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when the BIG-IP CGNAT Large Scale NAT (LSN) pool is configured on a virtual server and packet filtering is enabled, und…
- CVE-2022-28048HIGHCVSS 8.8EG 8.82022-04-15
STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
- CVE-2022-29978MEDIUMCVSS 6.5EG 6.52022-05-11
There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
- CVE-2022-30600CRITICALCVSS 9.8EG 9.82022-05-18
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
- CVE-2022-30780HIGHCVSS 7.5EG 8.22022-06-11
Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on …
- CVE-2022-31104MEDIUMCVSS 4.8EG 4.82022-06-28
Wasmtime is a standalone runtime for WebAssembly. In affected versions wasmtime's implementation of the SIMD proposal for WebAssembly on x86_64 contained two distinct bugs in the instruction lowerings implemented in Cranelift. The aarch64 …
- CVE-2022-31169MEDIUMCVSS 5.9EG 5.92022-07-22
Wasmtime is a standalone runtime for WebAssembly. There is a bug in Wasmtime's code generator, Cranelift, for AArch64 targets where constant divisors can result in incorrect division results at runtime. This affects Wasmtime prior to versi…
- CVE-2022-31198HIGHCVSS 7.5EG 7.52022-08-01
OpenZeppelin Contracts is a library for secure smart contract development. This issue concerns instances of Governor that use the module `GovernorVotesQuorumFraction`, a mechanism that determines quorum requirements as a percentage of the …
- CVE-2022-33972MEDIUMCVSS 6.1EG 6.12023-02-16
Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2022-35258HIGHCVSS 7.5EG 7.52022-12-05
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3…
- CVE-2022-36795HIGHCVSS 5.3EG 7.52022-10-19
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, and 14.1.x before 14.1.5.1, when an LTM TCP profile with Auto Receive Window Enabled is configured on a virtual server, undisclosed traffic can cause …
- CVE-2022-39242MEDIUMCVSS 5.3EG 5.32022-09-24
Frontier is an Ethereum compatibility layer for Substrate. Prior to commit d3beddc6911a559a3ecc9b3f08e153dbe37a8658, the worst case weight was always accounted as the block weight for all cases. In case of large EVM gas refunds, this can l…
- CVE-2023-1296LOWCVSS 2.7EG 2.72023-03-14
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.
- CVE-2023-2163CRITICALCVSS 10.0EG 10.02023-09-20
Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.
- CVE-2023-2423HIGHCVSS 8.6EG 8.62023-08-08
A vulnerability was discovered in the Rockwell Automation Armor PowerFlex device when the product sends communications to the local event log. Threat actors could exploit this vulnerability by sending an influx of network commands, causin…
- CVE-2023-24532MEDIUMCVSS 5.3EG 5.32023-03-08
The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/…
- CVE-2023-24533HIGHCVSS 7.5EG 7.52023-03-08
Multiplication of certain unreduced P-256 scalars produce incorrect results. There are no protocols known at this time that can be attacked due to this.
- CVE-2023-26488MEDIUMCVSS 6.5EG 6.52023-03-03
OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update balances when a batch has size 1 and consists of a single token. Subsequent tran…
- CVE-2023-28431HIGHCVSS 7.5EG 7.52023-03-22
Frontier is an Ethereum compatibility layer for Substrate. Frontier's `modexp` precompile uses `num-bigint` crate under the hood. In the implementation prior to pull request 1017, the cases for modulus being even and modulus being odd are …
- CVE-2023-31347MEDIUMCVSS 4.9EG 4.92024-02-13
Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.
- CVE-2023-3161MEDIUMCVSS 5.5EG 5.52023-06-12
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined b…
- CVE-2023-35641HIGHCVSS 8.8EG 8.82023-12-12
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
- CVE-2023-35642MEDIUMCVSS 6.5EG 6.52023-12-12
Internet Connection Sharing (ICS) Denial of Service Vulnerability
- CVE-2023-35848HIGHCVSS 7.5EG 7.52023-06-19
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 lacks certain size calculations before attempting to set a value of an mss structure member.
- CVE-2023-36980MEDIUMCVSS 5.3EG 5.32023-09-11
An issue in Ethereum Blockchain v0.1.1+commit.6ff4cd6 cause the balance to be zeroed out when the value of betsize+casino.balance exceeds the threshold.
- CVE-2023-42460HIGHCVSS 7.5EG 7.52023-09-27
Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is nested in an expression. Uses of `_abi_decode()` can be constructed which allow for bounds checking to be bypassed res…
- CVE-2023-43490MEDIUMCVSS 5.3EG 5.32024-03-14
Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2023-46247HIGHCVSS 7.5EG 7.52023-12-13
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Contracts containing large arrays might underallocate the number of slots they need by 1. Prior to v0.3.8, the calculation to determine how many slots a st…
- CVE-2023-7346MEDIUMCVSS 4.0EG 4.02026-05-20
Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: fra…
- CVE-2024-11176MEDIUMCVSS 5.3EG 5.32024-11-20
Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect evaluation of effective permissions.
Map vulnerabilities like CWE-682 to your infrastructure
EchelonGraph correlates every CVE — across CWE-682 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →