CWE-190: Integer Overflow

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

521
Total CVEs
104
Critical
297
High
7.8
Avg CVSS

Yearly Trend

2026
31
2025
154
2024
128
2023
83
2022
52

Top Affected Vendors

1 Linux 64
2 Google 55
3 Debian 46
4 Microsoft 43
5 Fedoraproject 33
6 Qualcomm 26
7 Adobe 17
8 Tonybybell 14
9 Redhat 13
10 Apple 12

All Integer Overflow CVEs (521)

CVE-2022-32073
9.8

CVE-2022-32073 is an integer overflow vulnerability in WolfSSH's SFTP server component that can lead to buffer overflow and potential remote code exec...

Jul 13, 2022
CVE-2022-25651
9.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via memory corruption in Qualcomm Bluetooth chips. It ...

Jun 14, 2022
CVE-2022-26775
9.8

CVE-2022-26775 is an integer overflow vulnerability in macOS that allows attackers to cause application crashes or execute arbitrary code. This affect...

May 26, 2022
CVE-2022-23943
9.8

CVE-2022-23943 is a critical heap memory corruption vulnerability in Apache HTTP Server's mod_sed module that allows attackers to write data beyond al...

Mar 14, 2022
CVE-2021-22480
9.8

CVE-2021-22480 is an integer overflow vulnerability in a HarmonyOS module interface that can lead to heap memory overflow when exploited. This vulnera...

Feb 25, 2022
CVE-2022-25315
9.8

CVE-2022-25315 is an integer overflow vulnerability in Expat's storeRawNames function that can lead to heap buffer overflow. This allows attackers to ...

Feb 18, 2022
CVE-2022-24310
9.8

This vulnerability allows attackers to trigger an integer overflow leading to heap-based buffer overflow in Schneider Electric's Interactive Graphical...

Feb 9, 2022
CVE-2021-41816
9.8

This vulnerability in Ruby's CGI.escape_html function allows integer overflow and buffer overflow when processing very long strings on platforms where...

Feb 6, 2022
CVE-2022-23852
9.8

CVE-2022-23852 is a signed integer overflow vulnerability in Expat (libexpat) XML parser that can lead to buffer overflow. When XML_CONTEXT_BYTES is c...

Jan 24, 2022
CVE-2021-30636
9.8

This vulnerability in MediaTek LinkIt SDK allows memory corruption through integer overflow during memory allocation functions. Attackers could potent...

Jan 24, 2022
CVE-2022-22822
9.8

CVE-2022-22822 is an integer overflow vulnerability in Expat's XML parser that can lead to heap buffer overflow. This allows attackers to execute arbi...

Jan 10, 2022
CVE-2022-22824
9.8

CVE-2022-22824 is an integer overflow vulnerability in Expat's defineAttribute function in xmlparse.c. This allows attackers to cause heap-based buffe...

Jan 10, 2022
CVE-2021-39993
9.8

This integer overflow vulnerability in Huawei smartphone ACPU components allows attackers to trigger out-of-bounds memory access. Successful exploitat...

Jan 10, 2022
CVE-2021-37095
9.8

This integer overflow vulnerability in Huawei smartphones allows attackers to cause denial of service or potentially execute arbitrary code remotely. ...

Dec 7, 2021
CVE-2021-20110
9.8

This vulnerability allows attackers to execute arbitrary code with SYSTEM privileges on ManageEngine Asset Explorer Agent installations by exploiting ...

Jul 19, 2021
CVE-2020-22874
9.8

This integer overflow vulnerability in jsish's Jsi_ObjArraySizer function allows remote attackers to execute arbitrary code by triggering memory corru...

Jul 13, 2021
CVE-2021-21807
9.8

This critical vulnerability in Accusoft ImageGear's DICOM parser allows remote code execution via integer overflow leading to stack buffer overflow. A...

Jul 7, 2021
CVE-2021-22323
9.8

This integer overflow vulnerability in Huawei smartphones allows attackers to escalate privileges to root access. It affects multiple Huawei smartphon...

Jun 30, 2021
CVE-2021-26461
9.8

CVE-2021-26461 is an integer overflow vulnerability in Apache NuttX memory allocation functions that allows attackers to trigger arbitrary memory allo...

Jun 21, 2021
CVE-2017-20005
9.8

This vulnerability is a buffer overflow in NGINX's autoindex module when processing file modification dates with years exceeding four digits. It affec...

Jun 6, 2021
CVE-2009-0947
9.8

Multiple integer overflow vulnerabilities in the file command's CDF parsing functions allow memory corruption when processing malicious files. This af...

Jun 2, 2021
CVE-2021-3520
9.8

CVE-2021-3520 is an integer overflow vulnerability in the LZ4 compression library that allows attackers to trigger out-of-bounds writes by submitting ...

Jun 2, 2021
CVE-2020-35198
9.8

CVE-2020-35198 is a critical integer overflow vulnerability in Wind River VxWorks 7's memory allocator that allows attackers to cause memory corruptio...

May 12, 2021
CVE-2020-28017
9.8

CVE-2020-28017 is an integer overflow vulnerability in Exim mail transfer agent that can lead to buffer overflow when processing emails with an excess...

May 6, 2021
CVE-2020-28020
9.8

CVE-2020-28020 is an integer overflow vulnerability in Exim mail transfer agent that leads to buffer overflow, allowing unauthenticated remote attacke...

May 6, 2021
CVE-2021-31870
9.8

CVE-2021-31870 is an integer overflow vulnerability in klibc's calloc() function that can lead to heap buffer overflow. This allows attackers to poten...

Apr 30, 2021
CVE-2021-31872
9.8

This vulnerability in klibc's cpio command allows integer overflows on 32-bit systems that can lead to buffer overflows. Attackers could potentially e...

Apr 30, 2021
CVE-2019-25032
9.8

CVE-2019-25032 is an integer overflow vulnerability in Unbound DNS resolver's regional allocator that could allow memory corruption. The vendor disput...

Apr 27, 2021
CVE-2019-25034
9.8

CVE-2019-25034 is an integer overflow vulnerability in Unbound DNS resolver's sldns_str2wire_dname_buf_origin function that can lead to out-of-bounds ...

Apr 27, 2021
CVE-2019-25038
9.8

CVE-2019-25038 is an integer overflow vulnerability in Unbound DNS resolver's dnscrypt component that could allow memory corruption. The vulnerability...

Apr 27, 2021
CVE-2021-31571
9.8

CVE-2021-31571 is an integer overflow vulnerability in Amazon Web Services FreeRTOS kernel's queue creation function. This allows attackers to cause h...

Apr 22, 2021
CVE-2021-28879
9.8

This vulnerability in Rust's standard library before version 1.52.0 involves an integer overflow in the Zip iterator implementation. When a consumed Z...

Apr 11, 2021
CVE-2021-3420
9.8

This CVE describes an integer overflow vulnerability in newlib memory allocation functions that can lead to heap-based buffer overflows. Attackers cou...

Mar 5, 2021
CVE-2020-11167
9.8

This is a critical memory corruption vulnerability in Qualcomm Snapdragon chipsets' Bluetooth L2CAP reassembly logic. Attackers can remotely execute a...

Jan 21, 2021
CVE-2020-11197
9.8

This CVE describes an integer overflow vulnerability in Qualcomm Snapdragon chipsets when parsing malformed TS clip data with zero streams. Successful...

Jan 21, 2021
CVE-2020-11184
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices by exploiting a buffer overflow in the vi...

Nov 12, 2020
CVE-2020-0452
9.8

This CVE describes an integer overflow vulnerability in Android's EXIF library that could allow remote code execution. Attackers can exploit this by s...

Nov 10, 2020
CVE-2023-6345
9.6

This CVE describes an integer overflow vulnerability in Skia (Chrome's graphics engine) that allows an attacker who has already compromised Chrome's r...

Nov 29, 2023
CVE-2023-2136
9.6

This vulnerability is an integer overflow in Google Chrome's Skia graphics library that allows an attacker who has already compromised the renderer pr...

Apr 19, 2023
CVE-2021-21223
9.6

This CVE describes an integer overflow vulnerability in Chrome's Mojo IPC framework that could allow a remote attacker who has already compromised the...

Apr 26, 2021
CVE-2025-23016
9.3

CVE-2025-23016 is an integer overflow vulnerability in FastCGI fcgi2 library versions 2.x through 2.4.4 that leads to heap-based buffer overflow when ...

Jan 10, 2025
CVE-2023-33032
9.3

This vulnerability allows memory corruption in the TrustZone Secure OS when requesting memory allocation from the Trusted Application region. It affec...

Jan 2, 2024
CVE-2021-30275
9.3

This vulnerability is an integer overflow in Qualcomm Snapdragon chipsets that could allow attackers to execute arbitrary code or cause denial of serv...

Jan 3, 2022
CVE-2026-2588
9.1

This CVE describes an integer overflow vulnerability in Crypt::NaCl::Sodium Perl module versions through 2.001 on 32-bit systems. The flaw occurs when...

Feb 23, 2026
CVE-2025-7458
9.1

An integer overflow vulnerability in SQLite's sqlite3KeyInfoFromExprList function allows attackers who can execute arbitrary SQL statements to cause d...

Jul 29, 2025
CVE-2024-35366
9.1

This CVE-2024-35366 is an integer overflow vulnerability in FFmpeg's libavformat module that allows attackers to cause denial of service or potentiall...

Nov 29, 2024
CVE-2024-5197
9.1

This CVE describes integer overflow vulnerabilities in libvpx (VP8/VP9 video codec library) that can occur when processing large image dimensions or a...

Jun 3, 2024
CVE-2022-28615
9.1

This vulnerability in Apache HTTP Server 2.4.53 and earlier could cause crashes or information disclosure due to a buffer overflow in the ap_strcmp_ma...

Jun 9, 2022
CVE-2021-35942
9.1

This vulnerability in glibc's wordexp function allows attackers to cause denial of service or potentially read arbitrary memory when processing malici...

Jul 22, 2021
CVE-2021-3402
9.1

CVE-2021-3402 is an integer overflow and buffer overflow vulnerability in YARA's Mach-O file parser that allows attackers to cause denial of service o...

May 14, 2021

About Integer Overflow (CWE-190)

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

Our database tracks 521 CVEs classified as CWE-190, with 104 rated critical and 297 rated high severity. The average CVSS score for Integer Overflow vulnerabilities is 7.8.

External reference: View CWE-190 on MITRE CWE →

Monitor Integer Overflow Vulnerabilities

Get alerted when new Integer Overflow CVEs affect your infrastructure.

Start Monitoring Free