CWE-190: Integer Overflow

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

529
Total CVEs
104
Critical
305
High
7.8
Avg CVSS

Yearly Trend

2026
31
2025
154
2024
128
2023
83
2022
52

Top Affected Vendors

1 Linux 64
2 Google 55
3 Debian 48
4 Microsoft 43
5 Fedoraproject 34
6 Qualcomm 27
7 Adobe 17
8 Tonybybell 14
9 Redhat 13
10 Oracle 13

All Integer Overflow CVEs (529)

CVE-2020-36242
9.1

This vulnerability in Python's cryptography package allows integer overflow and buffer overflow when encrypting multi-gigabyte values using symmetric ...

Feb 7, 2021
CVE-2019-16127
9.1

CVE-2019-16127 is an integer overflow vulnerability in Atmel Advanced Software Framework (ASF) 4's flash_read, flash_write, and flash_append functions...

Oct 22, 2020
CVE-2025-3500
9.0

An integer overflow vulnerability in Avast Antivirus for Windows allows attackers to escalate privileges on affected systems. This affects Avast Antiv...

Dec 1, 2025
CVE-2021-22156
9.0

An integer overflow vulnerability in the calloc() function of QNX runtime libraries allows attackers to cause denial of service or execute arbitrary c...

Aug 17, 2021
CVE-2025-41726
8.8

A low-privileged remote attacker can execute arbitrary code by sending specially crafted calls to the Device Manager web service or local API, exploit...

Jan 27, 2026
CVE-2026-0880
8.8

This CVE describes an integer overflow vulnerability in the Graphics component of Mozilla products that allows sandbox escape. Attackers could exploit...

Jan 13, 2026
CVE-2025-62496
8.8

This vulnerability allows attackers to trigger a heap out-of-bounds write by providing an excessively large BigInt string to QuickJS. Successful explo...

Oct 16, 2025
CVE-2025-58715
8.8

An integer overflow vulnerability in Microsoft Windows Speech components allows authenticated attackers to execute arbitrary code with elevated privil...

Oct 14, 2025
CVE-2025-10533
8.8

An integer overflow vulnerability in the SVG component of Mozilla products allows attackers to execute arbitrary code or cause denial of service. This...

Sep 16, 2025
CVE-2025-54110
8.8

An integer overflow vulnerability in the Windows Kernel allows authenticated attackers to escalate privileges locally. This affects Windows systems wh...

Sep 9, 2025
CVE-2025-55154
8.8

This vulnerability in ImageMagick allows integer overflow during PNG/MNG image processing, leading to memory corruption. Attackers can exploit this by...

Aug 13, 2025
CVE-2025-5478
8.8

This vulnerability allows attackers within Bluetooth range to execute arbitrary code with root privileges on Sony XAV-AX8500 infotainment systems with...

Jun 21, 2025
CVE-2025-5473
8.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious ICO files in GIMP. An integer overflow d...

Jun 6, 2025
CVE-2025-21243
8.8

This vulnerability in Windows Telephony Service allows remote attackers to execute arbitrary code on affected systems by sending specially crafted req...

Jan 14, 2025
CVE-2025-21244
8.8

This is a remote code execution vulnerability in the Windows Telephony Service that allows attackers to execute arbitrary code on affected systems. It...

Jan 14, 2025
CVE-2024-55656
8.8

An integer overflow vulnerability in RedisBloom's CMS.INITBYDIM command allows authenticated Redis clients to allocate less heap memory than required,...

Jan 8, 2025
CVE-2018-9472
8.8

CVE-2018-9472 is an integer overflow vulnerability in libxml2's xmlmemory.c that can lead to out-of-bounds write and remote code execution. It affects...

Nov 20, 2024
CVE-2024-38144
8.8

This vulnerability allows attackers to gain SYSTEM-level privileges on Windows systems by exploiting an integer overflow in the Kernel Streaming WOW T...

Aug 13, 2024
CVE-2024-37323
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of SQL Server Native Client OLE DB Provide...

Jul 9, 2024
CVE-2024-30064
8.8

CVE-2024-30064 is a Windows kernel elevation of privilege vulnerability that allows authenticated attackers to execute arbitrary code with SYSTEM priv...

Jun 11, 2024
CVE-2024-27833
8.8

This CVE describes an integer overflow vulnerability in Apple's WebKit browser engine that could allow arbitrary code execution when processing malici...

Jun 10, 2024
CVE-2023-40474
8.8

This CVE-2023-40474 vulnerability in GStreamer allows remote attackers to execute arbitrary code by exploiting an integer overflow when parsing malici...

May 3, 2024
CVE-2023-38104
8.8

This vulnerability in GStreamer's RealMedia file parser allows remote attackers to execute arbitrary code by exploiting an integer overflow when proce...

May 3, 2024
CVE-2023-37327
8.8

This vulnerability allows remote attackers to execute arbitrary code by exploiting an integer overflow in GStreamer's FLAC file parser. Attackers can ...

May 3, 2024
CVE-2024-28942
8.8

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending speciall...

Apr 9, 2024
CVE-2024-28936
8.8

This vulnerability in Microsoft ODBC Driver for SQL Server allows remote attackers to execute arbitrary code by sending specially crafted requests to ...

Apr 9, 2024
CVE-2024-21450
8.8

This vulnerability in Microsoft's WDAC OLE DB provider for SQL Server allows remote attackers to execute arbitrary code by exploiting an integer overf...

Mar 12, 2024
CVE-2024-21441
8.8

This vulnerability in Microsoft's WDAC OLE DB provider for SQL Server allows remote attackers to execute arbitrary code by exploiting an integer overf...

Mar 12, 2024
CVE-2024-23605
8.8

A heap-based buffer overflow vulnerability in the GGUF library header.n_kv functionality of llama.cpp allows remote code execution when processing mal...

Feb 26, 2024
CVE-2024-21836
8.8

A heap-based buffer overflow vulnerability in llama.cpp's GGUF library allows remote code execution when processing malicious .gguf files. This affect...

Feb 26, 2024
CVE-2024-21372
8.8

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems through malicious OLE objects. It affects Windows sys...

Feb 13, 2024
CVE-2023-47994
8.8

An integer overflow vulnerability in FreeImage's BMP plugin allows attackers to read memory contents, crash applications, or execute arbitrary code wh...

Jan 9, 2024
CVE-2023-5869
8.8

This CVE-2023-5869 vulnerability in PostgreSQL allows authenticated database users to execute arbitrary code on the server through an integer overflow...

Dec 10, 2023
CVE-2023-5849
8.8

This CVE describes an integer overflow vulnerability in Chrome's USB component that could allow heap corruption. Attackers could exploit this via a ma...

Nov 1, 2023
CVE-2023-42295
8.8

A buffer overflow vulnerability in OpenImageIO's read_rle_image function allows remote attackers to execute arbitrary code or cause denial of service....

Oct 23, 2023
CVE-2023-35673
8.8

This CVE describes an integer overflow vulnerability in Android's Bluetooth stack (gatt_sr.cc) that allows remote attackers within Bluetooth range to ...

Sep 11, 2023
CVE-2023-35315
8.8

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted packets to the Layer-2 B...

Jul 11, 2023
CVE-2023-24909
8.8

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting integer overflow in Microsoft PostScript and PC...

Mar 14, 2023
CVE-2023-24871
8.8

This vulnerability allows remote attackers to execute arbitrary code on Windows systems via the Bluetooth service without user interaction. It affects...

Mar 14, 2023
CVE-2023-21686
8.8

This vulnerability allows remote code execution through the Microsoft WDAC OLE DB provider for SQL Server. Attackers can exploit integer overflow (CWE...

Feb 14, 2023
CVE-2022-24845
8.8

This vulnerability in Vyper smart contract language allows integer overflow/underflow when using <iface>.returns_int128() in complex expressions, lead...

Apr 13, 2022
CVE-2022-0608
8.8

This vulnerability is an integer overflow in Chrome's Mojo IPC framework that could allow a remote attacker to trigger heap corruption by tricking use...

Apr 5, 2022
CVE-2022-25291
8.8

An integer overflow vulnerability in WatchGuard Firebox and XTM appliances allows authenticated remote attackers to trigger a heap-based buffer overfl...

Feb 24, 2022
CVE-2022-23587
8.8

This CVE describes an integer overflow vulnerability in TensorFlow's Grappler component during cost estimation for crop and resize operations. Attacke...

Feb 4, 2022
CVE-2022-22826
8.8

CVE-2022-22826 is an integer overflow vulnerability in Expat's XML parser that can lead to heap memory corruption. Attackers can exploit this by provi...

Jan 10, 2022
CVE-2021-42682
8.8

This integer overflow vulnerability in Accops HyWorks DVM Tools allows local attackers to execute arbitrary code with kernel privileges or crash the o...

Dec 7, 2021
CVE-2021-42685
8.8

This integer overflow vulnerability in Accops HyWorks DVM Tools allows local attackers to execute arbitrary code with kernel privileges or crash the o...

Dec 7, 2021
CVE-2021-42979
8.8

This vulnerability in NoMachine Cloud Server allows local attackers to execute arbitrary code with kernel privileges or cause denial of service throug...

Dec 7, 2021
CVE-2021-42987
8.8

CVE-2021-42987 is an integer overflow vulnerability in Eltima USB Network Gate's IOCTL handler that allows local attackers to execute arbitrary code w...

Dec 7, 2021
CVE-2021-43003
8.8

This vulnerability in Amzetta zPortal Windows zClient allows local attackers to execute arbitrary code with kernel privileges or cause denial of servi...

Dec 7, 2021

About Integer Overflow (CWE-190)

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

Our database tracks 529 CVEs classified as CWE-190, with 104 rated critical and 305 rated high severity. The average CVSS score for Integer Overflow vulnerabilities is 7.8.

External reference: View CWE-190 on MITRE CWE →

Monitor Integer Overflow Vulnerabilities

Get alerted when new Integer Overflow CVEs affect your infrastructure.

Start Monitoring Free