CWE-190: Integer Overflow

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

530
Total CVEs
104
Critical
306
High
7.8
Avg CVSS

Yearly Trend

2026
31
2025
154
2024
128
2023
83
2022
52

Top Affected Vendors

1 Linux 64
2 Google 55
3 Debian 49
4 Microsoft 43
5 Fedoraproject 34
6 Qualcomm 27
7 Adobe 17
8 Tonybybell 14
9 Redhat 13
10 Oracle 13

All Integer Overflow CVEs (530)

CVE-2021-38092
8.8

This integer overflow vulnerability in FFmpeg's convolution filter allows attackers to cause denial of service or potentially execute arbitrary code b...

Sep 20, 2021
CVE-2021-38094
8.8

This integer overflow vulnerability in FFmpeg's filter_sobel function allows attackers to cause denial of service or potentially execute arbitrary cod...

Sep 20, 2021
CVE-2020-20898
8.8

An integer overflow vulnerability in FFmpeg's convolution filter allows attackers to cause denial of service or potentially execute arbitrary code by ...

Sep 20, 2021
CVE-2021-38714
8.8

CVE-2021-38714 is an integer overflow vulnerability in Plib's ssgLoadTGA() function that can lead to arbitrary code execution when processing maliciou...

Aug 24, 2021
CVE-2020-19497
8.8

This integer overflow vulnerability in the MAT File I/O Library (matio) allows attackers to cause denial of service or potentially execute arbitrary c...

Jul 21, 2021
CVE-2021-29946
8.8

This vulnerability allows attackers to bypass port blocking restrictions by crafting Alt-Svc headers with integer overflow values above 65535. It affe...

Jun 24, 2021
CVE-2021-0557
8.8

This CVE describes an integer overflow vulnerability in Android's ABuffer.cpp that allows out-of-bounds writes. When exploited, it could lead to remot...

Jun 22, 2021
CVE-2021-31426
8.8

This vulnerability in Parallels Desktop allows local attackers with initial low-privileged access to escalate privileges to kernel-level execution thr...

Apr 29, 2021
CVE-2020-11269
8.8

This vulnerability allows memory corruption in Qualcomm Snapdragon chipsets when processing EAPOL frames due to insufficient validation of key length....

Feb 22, 2021
CVE-2020-28248
8.8

CVE-2020-28248 is an integer overflow vulnerability in the png-img library that leads to heap memory under-allocation and buffer overflow when process...

Feb 20, 2021
CVE-2025-11152
8.6

This CVE describes an integer overflow vulnerability in Firefox's Canvas2D graphics component that allows sandbox escape. Attackers could exploit this...

Sep 30, 2025
CVE-2024-44087
8.6

An integer overflow vulnerability in Siemens Automation License Manager allows unauthenticated remote attackers to crash the application via specially...

Sep 10, 2024
CVE-2024-34402
8.6

This vulnerability in uriparser allows attackers to trigger an integer overflow when processing long query keys or values, leading to buffer overflow....

May 3, 2024
CVE-2023-4576
8.6

This vulnerability is an integer overflow in Firefox's RecordedSourceSurfaceCreation function on Windows, leading to a heap buffer overflow. It could ...

Sep 11, 2023
CVE-2022-46720
8.6

This CVE describes an integer overflow vulnerability in Apple operating systems that allows malicious applications to escape their security sandbox. I...

May 8, 2023
CVE-2026-0861
8.4

An integer overflow vulnerability in GNU C Library's memalign functions (memalign, posix_memalign, aligned_alloc) can lead to heap corruption when bot...

Jan 14, 2026
CVE-2024-34733
8.4

This CVE describes an integer overflow vulnerability in the DevmemXIntMapPages function of devicemem_server.c that allows local privilege escalation t...

Jan 28, 2025
CVE-2024-36474
8.4

An integer overflow vulnerability in libgsf's Compound Document parser allows arbitrary code execution when processing malicious files. This affects a...

Oct 3, 2024
CVE-2024-42415
8.4

An integer overflow vulnerability in libgsf's Compound Document Binary File parser allows heap-based buffer overflow via specially crafted files, lead...

Oct 3, 2024
CVE-2024-33035
8.4

This vulnerability allows memory corruption in Qualcomm's gralloc memory allocator when clients request extremely high reserved sizes. Attackers could...

Sep 2, 2024
CVE-2024-33022
8.4

This vulnerability allows memory corruption in the HGSL driver when allocating memory, potentially leading to arbitrary code execution or system crash...

Aug 5, 2024
CVE-2023-28537
8.4

This vulnerability allows memory corruption in Qualcomm's audio processing module (COmxApeDec) due to integer overflow during memory allocation. Attac...

Aug 8, 2023
CVE-2023-22666
8.4

CVE-2023-22666 is a memory corruption vulnerability in Qualcomm's audio processing component when playing specially crafted AMR-WB+ audio clips. This ...

Aug 8, 2023
CVE-2022-0185
8.4

CVE-2022-0185 is a heap-based buffer overflow vulnerability in the Linux kernel's Filesystem Context API legacy handling. It allows a local attacker t...

Feb 11, 2022
CVE-2021-30274
8.4

This integer overflow vulnerability in Qualcomm Snapdragon chipsets allows attackers to potentially bypass access control mechanisms or execute arbitr...

Jan 3, 2022
CVE-2021-1912
8.4

This integer overflow vulnerability in Qualcomm Snapdragon chipsets could allow attackers to execute arbitrary code or cause denial of service. It aff...

Nov 12, 2021
CVE-2021-4206
8.2

This vulnerability in QEMU's QXL display device emulation allows a malicious privileged guest user to trigger an integer overflow and subsequent heap ...

Apr 29, 2022
CVE-2025-30712
8.1

This vulnerability in Oracle VM VirtualBox 7.1.6 allows a high-privileged attacker with local access to compromise the virtualization software, potent...

Apr 15, 2025
CVE-2024-51540
8.1

An arithmetic overflow vulnerability in Dell ECS retention period handling allows authenticated users with bucket/object access to bypass retention po...

Dec 26, 2024
CVE-2023-41056
8.1

This CVE describes an integer overflow vulnerability in Redis memory buffer resizing that can lead to heap overflow and potential remote code executio...

Jan 10, 2024
CVE-2023-24869
8.1

CVE-2023-24869 is a Remote Procedure Call Runtime Remote Code Execution Vulnerability that allows an attacker to execute arbitrary code on affected sy...

Mar 14, 2023
CVE-2023-23405
8.1

CVE-2023-23405 is a Remote Procedure Call Runtime Remote Code Execution Vulnerability that allows an attacker to execute arbitrary code on affected sy...

Mar 14, 2023
CVE-2021-46143
8.1

CVE-2021-46143 is an integer overflow vulnerability in Expat's XML parser that can lead to heap memory corruption. Attackers can exploit this by provi...

Jan 6, 2022
CVE-2025-52538
8.0

An integer overflow vulnerability in the XOCL driver allows local attackers to potentially read sensitive memory or crash systems. This affects system...

Nov 24, 2025
CVE-2023-28909
8.0

This vulnerability allows remote attackers to execute arbitrary code on affected Volkswagen MIB3 infotainment systems via Bluetooth. An integer overfl...

Jun 28, 2025
CVE-2024-20654
8.0

This vulnerability in Microsoft ODBC Driver allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected sys...

Jan 9, 2024
CVE-2024-36337
7.9

An integer overflow vulnerability in AMD NPU (Neural Processing Unit) Driver allows a local attacker to write out of bounds in kernel memory. This cou...

Apr 2, 2025
CVE-2026-21385
7.8

This CVE describes a memory corruption vulnerability in alignment-based memory allocation functions. Attackers can exploit this to execute arbitrary c...

Mar 2, 2026
CVE-2026-21347
7.8

Adobe Bridge versions 15.1.3, 16.0.1 and earlier contain an integer overflow vulnerability that could allow arbitrary code execution when a user opens...

Feb 10, 2026
CVE-2025-33218
7.8

An integer overflow vulnerability in NVIDIA's Windows GPU display driver kernel component (nvlddmkm.sys) could allow attackers to execute arbitrary co...

Jan 28, 2026
CVE-2025-33219
7.8

The NVIDIA Display Driver for Linux contains an integer overflow vulnerability in the kernel module that could allow local attackers to execute arbitr...

Jan 28, 2026
CVE-2026-24875
7.8

An integer overflow vulnerability in yoyofr modizer allows attackers to cause memory corruption by providing specially crafted input. This affects all...

Jan 27, 2026
CVE-2026-21673
7.8

This vulnerability involves integer overflow/underflow in the CIccXmlArrayType::ParseTextCountNum() function of iccDEV library, which could allow memo...

Jan 6, 2026
CVE-2025-15278
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of FontForge. Attackers can exploit this b...

Dec 31, 2025
CVE-2025-14422
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PNM image files in GIMP. The integer ove...

Dec 23, 2025
CVE-2025-14933
7.8

This vulnerability allows remote attackers to execute arbitrary code by exploiting an integer overflow in NSF Unidata NetCDF-C when processing malicio...

Dec 23, 2025
CVE-2025-66499
7.8

A heap-based buffer overflow vulnerability in Foxit PDF Reader's JBIG2 image parsing allows remote code execution when opening malicious PDF files. Th...

Dec 19, 2025
CVE-2025-47323
7.8

This vulnerability allows memory corruption when handling large GPR packets between user and root contexts in Qualcomm components. Attackers could pot...

Dec 18, 2025
CVE-2025-46285
7.8

An integer overflow vulnerability in Apple operating systems could allow malicious applications to gain root privileges. This affects multiple Apple p...

Dec 12, 2025
CVE-2025-36936
7.8

This vulnerability allows local privilege escalation through an integer overflow in the GetTachyonCommand function, leading to an out-of-bounds write....

Dec 11, 2025

About Integer Overflow (CWE-190)

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

Our database tracks 530 CVEs classified as CWE-190, with 104 rated critical and 306 rated high severity. The average CVSS score for Integer Overflow vulnerabilities is 7.8.

External reference: View CWE-190 on MITRE CWE →

Monitor Integer Overflow Vulnerabilities

Get alerted when new Integer Overflow CVEs affect your infrastructure.

Start Monitoring Free