CWE-190: Integer Overflow

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

520
Total CVEs
104
Critical
296
High
7.8
Avg CVSS

Yearly Trend

2026
31
2025
154
2024
128
2023
83
2022
52

Top Affected Vendors

1 Linux 64
2 Google 55
3 Debian 45
4 Microsoft 43
5 Fedoraproject 33
6 Qualcomm 26
7 Adobe 17
8 Tonybybell 14
9 Redhat 12
10 Apple 12

All Integer Overflow CVEs (520)

CVE-2025-64721
10.0

This vulnerability in Sandboxie allows sandboxed processes to exploit an integer overflow in the SbieSvc.exe service, leading to heap overflow and arb...

Dec 11, 2025
CVE-2026-2774
9.8

An integer overflow vulnerability in Firefox's Audio/Video component could allow attackers to execute arbitrary code or cause denial of service. This ...

Feb 24, 2026
CVE-2026-2762
9.8

An integer overflow vulnerability in Firefox's JavaScript Standard Library component could allow attackers to execute arbitrary code or cause denial o...

Feb 24, 2026
CVE-2026-24830
9.8

An integer overflow vulnerability in Ralim IronOS firmware allows attackers to cause memory corruption through improper arithmetic operations. This af...

Jan 27, 2026
CVE-2025-14308
9.8

An integer overflow vulnerability in Robocode's Buffer class write method allows attackers to manipulate data length, potentially causing buffer overf...

Dec 9, 2025
CVE-2025-27918
9.8

This vulnerability allows remote attackers to execute arbitrary code on AnyDesk clients by sending specially crafted UDP packets. The integer overflow...

Nov 6, 2025
CVE-2025-54957
9.8

This vulnerability in Dolby UDC allows remote attackers to cause a buffer overflow via a malformed DD+ bitstream, potentially leading to arbitrary cod...

Oct 20, 2025
CVE-2025-52581
9.8

An integer overflow vulnerability in libbiosig's GDF file parsing allows arbitrary code execution when processing malicious files. This affects applic...

Aug 25, 2025
CVE-2025-53518
9.8

An integer overflow vulnerability in libbiosig's ABF file parser allows arbitrary code execution when processing malicious files. This affects systems...

Aug 25, 2025
CVE-2025-30404
9.8

An integer overflow vulnerability in ExecuTorch's model loading functionality can cause overlapping memory allocations, potentially leading to arbitra...

Aug 7, 2025
CVE-2025-0838
9.8

This CVE describes a heap buffer overflow vulnerability in Abseil-cpp's hash containers where oversized size arguments can cause integer overflow and ...

Feb 21, 2025
CVE-2023-34399
9.8

This vulnerability in Mercedes-Benz NTG6 head units allows integer overflow in the Boost library when processing serialized archives via USB profile i...

Feb 13, 2025
CVE-2024-40765
9.8

An integer-based buffer overflow vulnerability in SonicOS IPSec implementation allows remote attackers to cause denial of service or potentially execu...

Jan 9, 2025
CVE-2024-50944
9.8

An integer overflow vulnerability in SimplCommerce's shopping cart functionality allows attackers to manipulate product quantities to cause buffer ove...

Dec 27, 2024
CVE-2024-49112
9.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running LDAP services by exploiting an integer overflow condit...

Dec 12, 2024
CVE-2024-47606
9.8

This vulnerability in GStreamer's qtdemux component allows integer underflow leading to heap corruption and arbitrary code execution. Attackers can ex...

Dec 12, 2024
CVE-2024-47537
9.8

This CVE describes an integer overflow vulnerability in GStreamer's QtDemux component that can lead to out-of-bounds memory writes. Attackers can expl...

Dec 12, 2024
CVE-2024-43091
9.8

This vulnerability allows remote code execution via an integer overflow in Skia's filterMask function, leading to out-of-bounds write. It affects Andr...

Nov 13, 2024
CVE-2024-46613
9.8

CVE-2024-46613 is an integer overflow vulnerability in WeeChat's string handling functions that leads to buffer overflow when processing lists with ov...

Nov 10, 2024
CVE-2024-46483
9.8

CVE-2024-46483 is an integer overflow vulnerability in Xlight FTP Server's SFTP packet parsing that leads to heap overflow with attacker-controlled co...

Oct 22, 2024
CVE-2024-45491
9.8

CVE-2024-45491 is an integer overflow vulnerability in libexpat's XML parsing library that can lead to heap buffer overflow on 32-bit platforms. This ...

Aug 30, 2024
CVE-2024-30949
9.8

A buffer overflow vulnerability in newlib's _gettimeofday function allows attackers to execute arbitrary code by exploiting improper time unit scaling...

Aug 20, 2024
CVE-2024-41184
9.8

CVE-2024-41184 is an integer overflow vulnerability in keepalived's vrrp_ipsets_handler that could lead to arbitrary code execution or denial of servi...

Jul 18, 2024
CVE-2024-1305
9.8

CVE-2024-1305 is an integer overflow vulnerability in the tap-windows6 driver (version 9.26 and earlier) that allows attackers to overflow memory buff...

Jul 8, 2024
CVE-2023-47212
9.8

A heap-based buffer overflow vulnerability in stb_vorbis.c allows attackers to execute arbitrary code or cause denial of service by providing a malici...

May 1, 2024
CVE-2024-32039
9.8

FreeRDP clients prior to versions 3.5.0 or 2.11.6 contain an integer overflow vulnerability that can lead to out-of-bounds writes when processing grap...

Apr 22, 2024
CVE-2024-1917
9.8

An integer overflow vulnerability in Mitsubishi Electric MELSEC-Q and MELSEC-L Series CPU modules allows remote unauthenticated attackers to execute a...

Mar 15, 2024
CVE-2024-22860
9.8

This integer overflow vulnerability in FFmpeg's JPEG XL Animation decoder allows remote attackers to execute arbitrary code by sending specially craft...

Jan 27, 2024
CVE-2023-52389
9.8

This CVE describes an integer overflow and stack buffer overflow vulnerability in POCO's UTF32Encoding component. When processing UTF-32 byte sequence...

Jan 27, 2024
CVE-2023-49262
9.8

This vulnerability allows attackers to bypass authentication by overflowing the 'authentication' cookie field when an active user session exists. It a...

Jan 12, 2024
CVE-2024-22051
9.8

CommonMarker versions before 0.23.4 have an integer overflow vulnerability when parsing markdown tables with more than 65,535 columns. This allows una...

Jan 4, 2024
CVE-2023-51714
9.8

This vulnerability is an integer overflow in the HPack table implementation of Qt's HTTP/2 component. It allows remote attackers to cause a denial of ...

Dec 24, 2023
CVE-2023-44709
9.8

CVE-2023-44709 is an integer overflow vulnerability in PlutoSVG's plutosvg_load_from_memory function that allows attackers to cause memory corruption....

Dec 14, 2023
CVE-2023-35967
9.8

Two heap-based buffer overflow vulnerabilities in Yifan YF325 routers allow remote attackers to execute arbitrary code or cause denial of service via ...

Oct 11, 2023
CVE-2023-35965
9.8

Two heap-based buffer overflow vulnerabilities in Yifan YF325 router's httpd manage_post functionality allow remote code execution via specially craft...

Oct 11, 2023
CVE-2023-35681
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Android devices via Bluetooth without user interaction. It affects An...

Sep 11, 2023
CVE-2023-36327
9.8

This integer overflow vulnerability in RELIC cryptographic library allows attackers to execute arbitrary code or cause denial of service by exploiting...

Sep 1, 2023
CVE-2023-35085
9.8

An integer overflow vulnerability in UniFi network devices with SNMP monitoring enabled allows remote attackers to execute arbitrary code. This affect...

Aug 10, 2023
CVE-2023-36910
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft Message Queuing (MSMQ) by sending specially crafted ...

Aug 8, 2023
CVE-2023-35385
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft Message Queuing (MSMQ) by sending specially crafted ...

Aug 8, 2023
CVE-2022-48336
9.8

This vulnerability involves an integer overflow in Widevine's PRDiagParseAndStoreData function, leading to a buffer overflow in the Trusted Applicatio...

Jun 26, 2023
CVE-2022-48334
9.8

This vulnerability is an integer overflow leading to buffer overflow in Widevine's drm_verify_keys function, allowing attackers to execute arbitrary c...

Jun 26, 2023
CVE-2022-48332
9.8

This vulnerability is an integer overflow in Widevine's drm_save_keys function that leads to a buffer overflow. It allows attackers to execute arbitra...

Jun 26, 2023
CVE-2022-48331
9.8

This vulnerability is an integer overflow and buffer overflow in Widevine's drm_save_keys function in Trusted Application versions 5.0.0 through 5.1.1...

Jun 26, 2023
CVE-2021-0701
9.8

This vulnerability is an integer overflow in the PowerVR kernel driver that allows out-of-bounds heap access. It enables local privilege escalation wi...

Jun 15, 2023
CVE-2023-33863
9.8

CVE-2023-33863 is an integer overflow vulnerability in RenderDoc's SerialiseValue function that leads to buffer overflow, potentially allowing remote ...

Jun 7, 2023
CVE-2023-23298
9.8

This vulnerability allows integer overflow in the BufferedBitmap.initialize API method in Garmin Connect IQ devices, enabling memory corruption and po...

May 23, 2023
CVE-2023-26065
9.8

This CVE describes an integer overflow vulnerability in certain Lexmark devices that could allow remote code execution. Attackers could exploit this t...

Apr 10, 2023
CVE-2023-28501
9.8

This critical vulnerability allows remote attackers to execute arbitrary code with root privileges on affected Rocket Software UniData and UniVerse sy...

Mar 29, 2023
CVE-2023-0754
9.8

This vulnerability is an integer overflow/wraparound in affected industrial control systems that could allow remote attackers to crash servers or exec...

Feb 23, 2023

About Integer Overflow (CWE-190)

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

Our database tracks 520 CVEs classified as CWE-190, with 104 rated critical and 296 rated high severity. The average CVSS score for Integer Overflow vulnerabilities is 7.8.

External reference: View CWE-190 on MITRE CWE →

Monitor Integer Overflow Vulnerabilities

Get alerted when new Integer Overflow CVEs affect your infrastructure.

Start Monitoring Free