CWE-190: Integer Overflow

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

530
Total CVEs
104
Critical
306
High
7.8
Avg CVSS

Yearly Trend

2026
31
2025
154
2024
128
2023
83
2022
52

Top Affected Vendors

1 Linux 64
2 Google 55
3 Debian 49
4 Microsoft 43
5 Fedoraproject 34
6 Qualcomm 27
7 Adobe 17
8 Tonybybell 14
9 Redhat 13
10 Oracle 13

All Integer Overflow CVEs (530)

CVE-2020-28009
7.8

CVE-2020-28009 is an integer overflow vulnerability in Exim mail transfer agent versions before 4.94.2. It allows remote attackers to cause buffer ove...

May 6, 2021
CVE-2021-29279
7.8

This integer overflow vulnerability in GPAC's filter_props.c allows attackers to trigger a memcpy failure by providing a negative size value, potentia...

Apr 19, 2021
CVE-2020-35523
7.8

An integer overflow vulnerability in libtiff's tif_getimage.c allows attackers to execute arbitrary code when a user opens a malicious TIFF file. This...

Mar 9, 2021
CVE-2020-12362
7.8

An integer overflow vulnerability in Intel Graphics Drivers for Windows and Linux kernel allows a privileged user to potentially escalate privileges v...

Feb 17, 2021
CVE-2020-12368
7.8

This CVE describes an integer overflow vulnerability in certain Intel Graphics Drivers that could allow a privileged user to escalate their privileges...

Feb 17, 2021
CVE-2021-26825
7.8

CVE-2021-26825 is an integer overflow vulnerability in Godot Engine that allows attackers to trigger a stack buffer overflow by loading specially craf...

Feb 8, 2021
CVE-2020-14409
7.8

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service via a specially crafted BMP image file. It affects app...

Jan 19, 2021
CVE-2021-1059
7.8

This vulnerability in NVIDIA vGPU manager allows attackers to cause integer overflow by providing unvalidated input indexes. Successful exploitation c...

Jan 8, 2021
CVE-2025-13601
7.7

A heap-based buffer overflow vulnerability in glib's g_escape_uri_string() function allows attackers to write beyond allocated memory boundaries when ...

Nov 26, 2025
CVE-2022-23558
7.6

This CVE describes an integer overflow vulnerability in TensorFlow's TFLite component where an attacker can craft a malicious TFLite model to trigger ...

Feb 4, 2022
CVE-2022-23562
7.6

This CVE describes an integer overflow vulnerability in TensorFlow's Range operation that can lead to undefined behavior or excessive memory allocatio...

Feb 4, 2022
CVE-2026-23833
7.5

An integer overflow vulnerability in ESPHome's API protobuf decoder allows denial-of-service attacks when API encryption is disabled. Malicious client...

Jan 19, 2026
CVE-2025-63757
7.5

An integer overflow vulnerability in FFmpeg's libswscale component allows attackers to cause heap corruption when processing specially crafted YUV vid...

Dec 18, 2025
CVE-2025-55753
7.5

An integer overflow in Apache HTTP Server's ACME certificate renewal process causes the backoff timer to reset to zero after approximately 30 days of ...

Dec 5, 2025
CVE-2025-63829
7.5

CVE-2025-63829 is an integer overflow vulnerability in eProsima Fast-DDS that causes an infinite loop in the Time_t::fraction() function. This allows ...

Nov 18, 2025
CVE-2025-12501
7.5

An integer overflow vulnerability in GameMaker IDE versions below 2024.14.0 can cause application crashes through denial-of-service attacks. This affe...

Oct 31, 2025
CVE-2025-59942
7.5

CVE-2025-59942 is an integer overflow vulnerability in go-f3's message validation that causes Filecoin nodes to panic and crash when processing specia...

Sep 29, 2025
CVE-2025-51495
7.5

An integer overflow vulnerability in Mongoose's WebSocket component (versions 7.5 through 7.17) allows attackers to crash applications via specially c...

Sep 29, 2025
CVE-2025-55552
7.5

CVE-2025-55552 is an integer overflow vulnerability in PyTorch v2.8.0 that occurs when torch.rot90 and torch.randn_like functions are used together, p...

Sep 25, 2025
CVE-2025-23323
7.5

NVIDIA Triton Inference Server contains an integer overflow vulnerability where sending an invalid request can cause a segmentation fault and crash th...

Aug 6, 2025
CVE-2025-23327
7.5

NVIDIA Triton Inference Server contains an integer overflow vulnerability (CWE-190) where specially crafted inputs could cause denial of service or da...

Aug 6, 2025
CVE-2025-52520
7.5

An integer overflow vulnerability in Apache Tomcat's multipart upload handling allows attackers to bypass configured size limits, potentially causing ...

Jul 10, 2025
CVE-2025-6021
7.5

This CVE describes an integer overflow vulnerability in libxml2's xmlBuildQName function that can cause stack-based buffer overflow when processing ma...

Jun 12, 2025
CVE-2025-31221
7.5

This CVE describes an integer overflow vulnerability in multiple Apple operating systems that could allow a remote attacker to leak memory. The vulner...

May 12, 2025
CVE-2025-2082
7.5

This vulnerability allows network-adjacent attackers to execute arbitrary code on Tesla Model 3 vehicles by exploiting an integer overflow in the VCSE...

Apr 30, 2025
CVE-2024-33063
7.5

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted beacon frames with malformed Multi-Lin...

Dec 2, 2024
CVE-2024-42384
7.5

An integer overflow vulnerability in Cesanta Mongoose Web Server v7.14 allows attackers to crash the server by sending specially crafted TLS packets. ...

Nov 18, 2024
CVE-2024-52912
7.5

This vulnerability in Bitcoin Core allows attackers to cause a network split by exploiting an integer overflow when calculating time offsets for new p...

Nov 18, 2024
CVE-2022-20685
7.5

An integer overflow vulnerability in Snort's Modbus preprocessor allows remote attackers to cause denial of service by sending crafted Modbus traffic....

Nov 15, 2024
CVE-2023-45854
7.5

An integer overflow vulnerability in Shopkit 1.0 allows attackers to add products with negative quantities to shopping carts via the qtd parameter. Th...

Sep 16, 2024
CVE-2024-33024
7.5

This vulnerability allows an attacker to cause a Denial of Service (DoS) by sending specially crafted Wi-Fi beacon frames with malformed Multi-Link (M...

Aug 5, 2024
CVE-2023-33976
7.5

CVE-2023-33976 is a vulnerability in TensorFlow's array_ops.upper_bound function that causes a segmentation fault when provided with a tensor that is ...

Jul 30, 2024
CVE-2023-49441
7.5

CVE-2023-49441 is an integer overflow vulnerability in dnsmasq's forward_query function that could allow remote attackers to cause a denial of service...

Jun 6, 2024
CVE-2024-23775
7.5

An integer overflow vulnerability in Mbed TLS's mbedtls_x509_set_extension() function allows attackers to cause denial of service (DoS) by triggering ...

Jan 31, 2024
CVE-2024-22861
7.5

An integer overflow vulnerability in FFmpeg's avcodec/osq module allows attackers to cause denial of service (DoS) by triggering crashes or resource e...

Jan 27, 2024
CVE-2023-43826
7.5

This vulnerability in Apache Guacamole allows integer overflow when processing malicious VNC server data, potentially leading to memory corruption and...

Dec 19, 2023
CVE-2023-4398
7.5

An integer overflow vulnerability in the QuickSec IPSec toolkit used in Zyxel VPN devices allows unauthenticated attackers to cause denial-of-service ...

Nov 28, 2023
CVE-2023-36395
7.5

This vulnerability in Windows Deployment Services (WDS) allows attackers to cause a denial of service by sending specially crafted packets to vulnerab...

Nov 14, 2023
CVE-2023-36478
7.5

This CVE describes an integer overflow vulnerability in Eclipse Jetty's HTTP/2 HPACK header processing. Attackers can send specially crafted HTTP/2 re...

Oct 10, 2023
CVE-2023-28831
7.5

This CVE describes an integer overflow vulnerability in OPC UA implementations (ANSI C and C++) that causes infinite loops during certificate validati...

Sep 12, 2023
CVE-2020-21699
7.5

CVE-2020-21699 is an integer overflow vulnerability in Tengine's range filter module that allows attackers to leak potentially sensitive information f...

Aug 22, 2023
CVE-2023-39125
7.5

CVE-2023-39125 is an integer overflow and out-of-bounds write vulnerability in NTSC-CRT's BMP loading function. Attackers can exploit this by providin...

Aug 18, 2023
CVE-2023-20689
7.5

This CVE describes an integer overflow vulnerability in MediaTek wlan firmware that can cause system crashes. Attackers can remotely trigger denial of...

Jul 4, 2023
CVE-2023-20691
7.5

This CVE describes an integer overflow vulnerability in MediaTek wlan firmware that can cause system crashes. Attackers can remotely trigger denial of...

Jul 4, 2023
CVE-2023-20693
7.5

This vulnerability in MediaTek wlan firmware allows remote attackers to cause a system crash (denial of service) without authentication or user intera...

Jul 4, 2023
CVE-2023-21193
7.5

This CVE describes an integer overflow vulnerability in Android's VideoFrame component that could allow remote information disclosure without user int...

Jun 28, 2023
CVE-2020-20335
7.5

A buffer overflow vulnerability in the Kilo text editor allows remote attackers to cause denial of service by exploiting the editorUpdateRow function....

Jun 20, 2023
CVE-2023-32058
7.5

CVE-2023-32058 is an integer overflow vulnerability in Vyper smart contract language where loop iterator variables can overflow their type bounds when...

May 11, 2023
CVE-2023-30463
7.5

CVE-2023-30463 is an integer overflow vulnerability in Altran picoTCP's IPv6 implementation that allows memory corruption when processing large ICMPv6...

Apr 19, 2023
CVE-2023-25662
7.5

CVE-2023-25662 is an integer overflow vulnerability in TensorFlow's EditDistance function that could allow attackers to cause denial of service or pot...

Mar 25, 2023

About Integer Overflow (CWE-190)

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

Our database tracks 530 CVEs classified as CWE-190, with 104 rated critical and 306 rated high severity. The average CVSS score for Integer Overflow vulnerabilities is 7.8.

External reference: View CWE-190 on MITRE CWE →

Monitor Integer Overflow Vulnerabilities

Get alerted when new Integer Overflow CVEs affect your infrastructure.

Start Monitoring Free