CWE-682— Incorrect Calculation
The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.— MITRE CWE catalog
150 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-682page 2 of 3
- CVE-2026-10512HIGHCVSS 7.5EG 7.52026-06-25
The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so the computed result may not be fully reduced modulo the field prime 2^255 - 19. This can leave the field element in a …
- CVE-2026-44498HIGHCVSS 7.5EG 7.52026-05-08
ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd r…
- CVE-2026-33487HIGHCVSS 7.5EG 7.52026-03-26
goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID. I…
- CVE-2026-24783HIGHCVSS 7.5EG 7.52026-01-27
soroban-fixed-point-math is a fixed-point math library for Soroban smart contacts. In versions 1.3.0 and 1.4.0, the `mulDiv(x, y, z)` function incorrectly handled cases where both the intermediate product $x * y$ and the divisor $z$ were n…
- CVE-2025-55552HIGHCVSS 7.5EG 7.52025-09-25
pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
- CVE-2025-4435HIGHCVSS 7.5EG 7.52025-06-03
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that …
- CVE-2025-26622HIGHCVSS 7.5EG 7.52025-02-21
vyper is a Pythonic Smart Contract Language for the EVM. Vyper `sqrt()` builtin uses the babylonian method to calculate square roots of decimals. Unfortunately, improper handling of the oscillating final states may lead to sqrt incorrectly…
- CVE-2024-11407HIGHCVSS 7.5EG 7.52024-11-26
There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_ARG_TCP_TX_ZEROCOPY_ENABLED can experience data corruption issues. The data sent by the a…
- CVE-2024-6287HIGHCVSS 7.5EG 7.52024-06-24
Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. When checking whether a new image invades/overlaps with a previously loaded image the code neglects to consider a few cases. that could A…
- CVE-2023-46247HIGHCVSS 7.5EG 7.52023-12-13
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Contracts containing large arrays might underallocate the number of slots they need by 1. Prior to v0.3.8, the calculation to determine how many slots a st…
- CVE-2023-42460HIGHCVSS 7.5EG 7.52023-09-27
Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is nested in an expression. Uses of `_abi_decode()` can be constructed which allow for bounds checking to be bypassed res…
- CVE-2023-35848HIGHCVSS 7.5EG 7.52023-06-19
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 lacks certain size calculations before attempting to set a value of an mss structure member.
- CVE-2023-28431HIGHCVSS 7.5EG 7.52023-03-22
Frontier is an Ethereum compatibility layer for Substrate. Frontier's `modexp` precompile uses `num-bigint` crate under the hood. In the implementation prior to pull request 1017, the cases for modulus being even and modulus being odd are …
- CVE-2023-24533HIGHCVSS 7.5EG 7.52023-03-08
Multiplication of certain unreduced P-256 scalars produce incorrect results. There are no protocols known at this time that can be attacked due to this.
- CVE-2022-35258HIGHCVSS 7.5EG 7.52022-12-05
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3…
- CVE-2022-31198HIGHCVSS 7.5EG 7.52022-08-01
OpenZeppelin Contracts is a library for secure smart contract development. This issue concerns instances of Governor that use the module `GovernorVotesQuorumFraction`, a mechanism that determines quorum requirements as a percentage of the …
- CVE-2022-22138HIGHCVSS 7.5EG 7.52022-06-17
All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault…
- CVE-2021-44504HIGHCVSS 7.5EG 7.52022-04-15
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a size variable, stored as an signed int, to equal an extremely large value, which is interpreted as a nega…
- CVE-2021-44491HIGHCVSS 7.5EG 7.52022-04-15
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a …
- CVE-2021-44490HIGHCVSS 7.5EG 7.52022-04-15
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a …
- CVE-2022-23011HIGHCVSS 7.5EG 7.52022-01-25
On certain hardware BIG-IP platforms, in version 15.1.x before 15.1.4 and 14.1.x before 14.1.3, virtual servers may stop responding while processing TCP traffic due to an issue in the SYN Cookie Protection feature. Note: Software versions …
- CVE-2020-28393HIGHCVSS 7.5EG 7.52021-05-12
An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device on the SCALANCE XM-400, XR-500 (Al…
- CVE-2021-3004HIGHCVSS 7.5EG 7.52021-01-03
The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should.
- CVE-2020-28030HIGHCVSS 7.5EG 7.52020-11-02
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
- CVE-2019-2232HIGHCVSS 7.5EG 7.52019-12-06
In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service when processing Unicode with no additional execution privileges needed. User interaction is …
- CVE-2019-17514HIGHCVSS 7.5EG 7.52019-10-12
library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether sorting occurs, as demonstrated by irreproducible cancer-research results. NOTE: the effects of this documentation cross…
- CVE-2018-20999HIGHCVSS 7.5EG 7.52019-08-26
An issue was discovered in the orion crate before 0.11.2 for Rust. reset() calls cause incorrect results.
- CVE-2018-18225HIGHCVSS 7.5EG 7.52018-10-12
In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.
- CVE-2018-15391HIGHCVSS 7.5EG 7.52018-10-05
A vulnerability in certain IPv4 fragment-processing functions of Cisco Remote PHY Software could allow an unauthenticated, remote attacker to impact traffic passing through a device, potentially causing a denial of service (DoS) condition.…
- CVE-2018-14439HIGHCVSS 7.5EG 7.52018-07-20
espritblock eos4j, an unofficial SDK for EOS, through 2018-07-12 mishandles floating-point numbers with more than four digits after the decimal point, which might allow attackers to trigger currency transfers of unintended amounts.
- CVE-2017-0819HIGHCVSS 7.5EG 7.52017-10-04
A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63045918.
- CVE-2022-26517HIGHCVSS 5.9EG 7.52022-05-05
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when the BIG-IP CGNAT Large Scale NAT (LSN) pool is configured on a virtual server and packet filtering is enabled, und…
- CVE-2022-36795HIGHCVSS 5.3EG 7.52022-10-19
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, and 14.1.x before 14.1.5.1, when an LTM TCP profile with Auto Receive Window Enabled is configured on a virtual server, undisclosed traffic can cause …
- CVE-2019-1918HIGHCVSS 7.4EG 7.42019-08-07
A vulnerability in the implementation of Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS-IS area to …
- CVE-2020-26262HIGHCVSS 7.2EG 7.22021-01-13
Coturn is free open source implementation of TURN and STUN Server. Coturn before version 4.5.2 by default does not allow peers to connect and relay packets to loopback addresses in the range of `127.x.x.x`. However, it was observed that wh…
- CVE-2026-0810HIGHCVSS 7.1EG 7.12026-01-26
A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `TimeBuf` component, leading to undefined …
- CVE-2021-31440HIGHCVSS 7.0EG 7.02021-05-21
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vuln…
- CVE-2025-54427MEDIUMCVSS 6.9EG 6.92025-07-28
Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. The extrinsic note_min_gas_price_target is an inherent extrinsic, meaning only the block producer can call it. To ensure correctness, the ProvideInher…
- CVE-2011-3062MEDIUMCVSS v2 6.8EG 6.82012-03-30
Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted OpenType file.
- CVE-2026-21911MEDIUMCVSS 6.5EG 6.52026-01-15
An Incorrect Calculation vulnerability in the Layer 2 Control Protocol Daemon (l2cpd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker flapping the management interface to cause the learning of n…
- CVE-2023-35642MEDIUMCVSS 6.5EG 6.52023-12-12
Internet Connection Sharing (ICS) Denial of Service Vulnerability
- CVE-2023-26488MEDIUMCVSS 6.5EG 6.52023-03-03
OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update balances when a batch has size 1 and consists of a single token. Subsequent tran…
- CVE-2022-29978MEDIUMCVSS 6.5EG 6.52022-05-11
There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
- CVE-2021-41329MEDIUMCVSS 6.5EG 6.52021-09-27
Datalust Seq before 2021.2.6259 allows users (with view filters applied to their accounts) to see query results not constrained by their view filter. This information exposure, caused by an internal cache key collision, occurs when the use…
- CVE-2021-29945MEDIUMCVSS 6.5EG 6.52021-06-24
The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32 platforms. Other platforms are unaffected.*. This vulnerability affects Firefox…
- CVE-2021-3114MEDIUMCVSS 6.5EG 6.52021-01-26
In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.
- CVE-2020-26241MEDIUMCVSS 6.5EG 6.52020-11-25
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. This is a Consensus vulnerability in Geth before version 1.9.17 which can be used to cause a chain-split where vulnerable nodes reject the canonical ch…
- CVE-2020-27616MEDIUMCVSS 6.5EG 6.52020-11-06
ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a calculation. A guest can crash the QEMU process.
- CVE-2019-11474MEDIUMCVSS 6.5EG 6.52019-04-23
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
- CVE-2018-16781MEDIUMCVSS 6.5EG 6.52018-09-10
ffjpeg.dll in ffjpeg before 2018-08-22 allows remote attackers to cause a denial of service (FPE signal) via a progressive JPEG file that lacks an AC Huffman table.
Map vulnerabilities like CWE-682 to your infrastructure
EchelonGraph correlates every CVE — across CWE-682 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →