CWE-190: Integer Overflow

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

537
Total CVEs
105
Critical
312
High
7.8
Avg CVSS

Yearly Trend

2026
31
2025
154
2024
128
2023
83
2022
52

Top Affected Vendors

1 Linux 64
2 Google 57
3 Debian 51
4 Microsoft 43
5 Fedoraproject 34
6 Qualcomm 27
7 Adobe 17
8 Tonybybell 14
9 Redhat 13
10 Apple 13

All Integer Overflow CVEs (537)

CVE-2022-48938
5.5

This CVE describes an integer overflow vulnerability in the Linux kernel's CDC-NCM network driver. A malicious or broken USB device could trigger this...

Aug 22, 2024
CVE-2024-43838
5.5

A Linux kernel BPF subsystem vulnerability allows incorrect overflow checking in jump offset calculations, potentially enabling local privilege escala...

Aug 17, 2024
CVE-2024-42066
5.5

This CVE describes an integer overflow vulnerability in the Linux kernel's Xe graphics driver. The flaw occurs during page size calculations and could...

Jul 29, 2024
CVE-2024-37356
5.5

This CVE describes an integer overflow vulnerability in the Linux kernel's DCTCP congestion control module. Attackers with local access can trigger a ...

Jun 21, 2024
CVE-2024-36918
5.5

A missing size check in the Linux kernel's BPF bloom filter map implementation allows attackers to trigger integer overflows when creating maps with v...

May 30, 2024
CVE-2023-52762
5.5

This CVE describes an integer overflow vulnerability in the Linux kernel's virtio-blk driver. When virtio_max_dma_size() returns a value larger than U...

May 21, 2024
CVE-2023-52676
5.5

This CVE-2023-52676 is an integer overflow vulnerability in the Linux kernel's BPF verifier that could allow local attackers to bypass stack limit che...

May 17, 2024
CVE-2024-35827
5.5

This CVE describes an integer overflow vulnerability in the Linux kernel's io_uring subsystem. The flaw occurs when processing network messages, where...

May 17, 2024
CVE-2025-66168
5.4

Apache ActiveMQ has an integer overflow vulnerability in MQTT packet handling that allows malformed packets to cause unexpected broker behavior. This ...

Mar 4, 2026
CVE-2026-27951
5.3

This vulnerability in FreeRDP's Stream_EnsureCapacity function can cause an endless blocking loop, potentially leading to denial of service. It affect...

Feb 25, 2026
CVE-2026-24889
5.3

This vulnerability in soroban-sdk allows arithmetic overflow in slice and random number generation methods, potentially causing contracts to operate o...

Jan 28, 2026
CVE-2025-69204
5.3

ImageMagick versions before 7.1.2-12 contain an integer overflow vulnerability in the WriteSVGImage function that can trigger a buffer overflow. This ...

Dec 30, 2025
CVE-2025-55554
5.3

PyTorch v2.8.0 contains an integer overflow vulnerability in torch.nan_to_num-.long() that could allow memory corruption or denial of service. This af...

Sep 25, 2025
CVE-2025-58749
5.3

This vulnerability in WebAssembly Micro Runtime (WAMR) causes runtime hangs or crashes when executing WebAssembly programs with specific memory.fill i...

Sep 16, 2025
CVE-2025-25248
5.3

An integer overflow vulnerability in Fortinet SSL-VPN RDP/VNC bookmarks allows authenticated users to craft requests that may crash the SSL-VPN servic...

Aug 12, 2025
CVE-2025-47294
5.3

An integer overflow vulnerability in Fortinet FortiOS allows remote unauthenticated attackers to crash the csfd daemon via specially crafted requests....

May 28, 2025
CVE-2024-7488
5.3

This vulnerability in RestApp Inc.'s Online Ordering System allows attackers to exploit integer overflow/wraparound issues by providing malicious inpu...

Dec 4, 2024
CVE-2024-36619
5.3

CVE-2024-36619 is an integer overflow vulnerability in FFmpeg's WAVARC decoder that can cause a denial-of-service condition when processing specially ...

Nov 29, 2024
CVE-2024-34663
5.3

An integer overflow vulnerability in libSEF.quram.so allows local attackers to write out-of-bounds memory, potentially leading to privilege escalation...

Oct 8, 2024
CVE-2024-21783
4.8

An integer overflow vulnerability in Intel VPL software allows authenticated local users to potentially escalate privileges. This affects systems runn...

Nov 13, 2024
CVE-2024-40635
4.6

A vulnerability in containerd allows containers launched with UID/GID values exceeding 32-bit signed integer limits to overflow and run as root (UID 0...

Mar 17, 2025
CVE-2025-48174
4.5

This vulnerability in libavif (AV1 Image File Format library) involves an integer overflow in the makeRoom function in stream.c, which can lead to a b...

May 16, 2025
CVE-2025-67125
4.4

This CVE describes a signed integer overflow vulnerability in docopt.cpp v0.6.2 that occurs when merging occurrence counters. Attackers can bypass log...

Jan 23, 2026
CVE-2024-42131
4.4

This CVE-2024-42131 is an integer overflow vulnerability in the Linux kernel's dirty page throttling logic that could lead to kernel instability or cr...

Jul 30, 2024
CVE-2025-59800
4.3

This CVE describes an integer overflow vulnerability in Artifex Ghostscript's PDF OCR device that leads to heap-based buffer overflow when processing ...

Sep 22, 2025
CVE-2024-21844
4.3

An integer overflow vulnerability in Intel Converged Security and Management Engine (CSME) firmware allows unauthenticated attackers on the same netwo...

Aug 14, 2024
CVE-2021-26377
4.1

This vulnerability in AMD's Trusted OS (TOS) allows a malicious userspace process to trigger an integer overflow by exploiting insufficient parameter ...

Sep 6, 2025
CVE-2024-45778
4.1

A stack overflow vulnerability in GRUB2's BFS filesystem parser allows an attacker to crash the bootloader by providing a specially crafted BFS filesy...

Mar 3, 2025
CVE-2025-32364
4.0

A floating-point exception vulnerability in Poppler's PSStack::roll function allows attackers to cause denial of service by crashing applications that...

Apr 5, 2025
CVE-2026-0988
3.7

An integer overflow vulnerability in glib's g_buffered_input_stream_peek() function allows attackers to trigger a buffer overflow by providing special...

Jan 21, 2026
CVE-2023-29144
3.3

Malwarebytes 1.0.14 for Linux has a signature computation vulnerability that allows malware to bypass detection. This affects Linux systems running th...

Dec 12, 2025
CVE-2026-0619
N/A

An integer wraparound vulnerability in Silicon Labs' Matter SDK creates an infinite loop that causes denial of service. Attackers can trigger this to ...

Feb 12, 2026
CVE-2026-24808
N/A

An integer overflow vulnerability in RawTherapee's rtengine modules could allow attackers to cause denial of service or potentially execute arbitrary ...

Jan 27, 2026
CVE-2026-24814
N/A

An integer overflow vulnerability in the hiredis module of swoole-src allows attackers to cause memory corruption through specially crafted input. Thi...

Jan 27, 2026
CVE-2026-1464
N/A

An integer overflow vulnerability in the Apache Commons Compress TarUtils module used by AppManager allows attackers to cause denial of service or pot...

Jan 27, 2026
CVE-2025-69261
N/A

A vulnerability in WasmEdge WebAssembly runtime allows integer overflow in memory boundary checking, leading to segmentation faults. This affects all ...

Dec 30, 2025
CVE-2025-34297
N/A

This CVE describes an integer overflow vulnerability in KissFFT library versions prior to fix commit 1b083165. On 32-bit architectures, an attacker ca...

Dec 1, 2025

About Integer Overflow (CWE-190)

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

Our database tracks 537 CVEs classified as CWE-190, with 105 rated critical and 312 rated high severity. The average CVSS score for Integer Overflow vulnerabilities is 7.8.

External reference: View CWE-190 on MITRE CWE →

Monitor Integer Overflow Vulnerabilities

Get alerted when new Integer Overflow CVEs affect your infrastructure.

Start Monitoring Free