CWE-190: Integer Overflow

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

530
Total CVEs
104
Critical
306
High
7.8
Avg CVSS

Yearly Trend

2026
31
2025
154
2024
128
2023
83
2022
52

Top Affected Vendors

1 Linux 64
2 Google 55
3 Debian 49
4 Microsoft 43
5 Fedoraproject 34
6 Qualcomm 27
7 Adobe 17
8 Tonybybell 14
9 Redhat 13
10 Oracle 13

All Integer Overflow CVEs (530)

CVE-2023-0705
7.5

This integer overflow vulnerability in Google Chrome's Core component allows remote attackers to potentially exploit heap corruption via a crafted HTM...

Feb 7, 2023
CVE-2022-28937
7.5

This vulnerability in FISCO-BCOS blockchain nodes allows a malicious node to send invalid proposals with bad headers, causing normal nodes to stop pro...

May 15, 2022
CVE-2021-39762
7.5

CVE-2021-39762 is an integer overflow vulnerability in Android's tremolo audio decoder that could allow remote attackers to read memory beyond intende...

Mar 30, 2022
CVE-2022-0913
7.5

This integer overflow vulnerability in Microweber CMS allows attackers to cause denial of service or potentially execute arbitrary code by triggering ...

Mar 11, 2022
CVE-2021-22319
7.5

CVE-2021-22319 is an integer overflow vulnerability in Huawei smartphones that occurs due to improper input validation. Successful exploitation could ...

Feb 25, 2022
CVE-2022-25314
7.5

CVE-2022-25314 is an integer overflow vulnerability in Expat's copyString function that can lead to heap buffer overflow. This allows attackers to pot...

Feb 18, 2022
CVE-2022-23772
7.5

CVE-2022-23772 is an integer overflow vulnerability in Go's math/big.Rat.SetString function that allows attackers to trigger uncontrolled memory consu...

Feb 11, 2022
CVE-2022-24667
7.5

CVE-2022-24667 is a denial-of-service vulnerability in swift-nio-http2 where a malicious HTTP/2 peer can send specially crafted HPACK-encoded header b...

Feb 9, 2022
CVE-2021-46389
7.5

CVE-2021-46389 is an integer overflow vulnerability in IIPImage High Resolution Streaming Image Server that allows remote attackers to cause a denial ...

Feb 7, 2022
CVE-2021-46102
7.5

This integer overflow vulnerability in Solana rBPF's ELF relocation function allows attackers to trigger memory corruption by providing specially craf...

Jan 27, 2022
CVE-2022-23990
7.5

CVE-2022-23990 is an integer overflow vulnerability in Expat (libexpat) XML parser library that can lead to denial of service or arbitrary code execut...

Jan 26, 2022
CVE-2021-38787
7.5

An integer overflow vulnerability exists in the ION driver of Allwinner R818 SoC Android Q SDK V1.0. Attackers can exploit this via the COMPAT_ION_IOC...

Jan 19, 2022
CVE-2021-43618
7.5

CVE-2021-43618 is an integer overflow vulnerability in GNU Multiple Precision Arithmetic Library (GMP) that leads to buffer overflow when processing c...

Nov 15, 2021
CVE-2021-0630
7.5

This CVE describes a buffer overflow vulnerability in MediaTek Wi-Fi drivers where missing bounds checking could allow remote attackers to crash affec...

Oct 25, 2021
CVE-2021-41990
7.5

CVE-2021-41990 is an integer overflow vulnerability in the gmp plugin of strongSwan VPN software. Attackers can trigger this by sending a specially cr...

Oct 18, 2021
CVE-2021-32762
7.5

This CVE describes an integer overflow vulnerability in Redis' hiredis library that affects redis-cli and redis-sentinel when parsing large multi-bulk...

Oct 4, 2021
CVE-2021-41099
7.5

CVE-2021-41099 is an integer overflow vulnerability in Redis' string library that allows heap corruption when the proto-max-bulk-len configuration is ...

Oct 4, 2021
CVE-2021-32627
7.5

CVE-2021-32627 is an integer overflow vulnerability in Redis that allows remote attackers to corrupt heap memory by setting configuration parameters t...

Oct 4, 2021
CVE-2021-40346
7.5

CVE-2021-40346 is an integer overflow vulnerability in HAProxy's HTTP header processing that enables HTTP request smuggling attacks. This allows attac...

Sep 8, 2021
CVE-2021-33403
7.5

An integer overflow vulnerability in the transfer function of the Lancer Token (LNCToken) smart contract allows the contract owner to manipulate token...

Aug 3, 2021
CVE-2021-22412
7.5

This integer overflow vulnerability in Huawei smartphones allows attackers to access random kernel memory addresses when exploited. It affects Huawei ...

Aug 2, 2021
CVE-2021-31292
7.5

This CVE describes an integer overflow vulnerability in Exiv2's CrwMap::encode0x1810 function that allows attackers to trigger a heap-based buffer ove...

Jul 26, 2021
CVE-2021-20312
7.5

This CVE describes an integer overflow vulnerability in ImageMagick's thumbnail generation function. Attackers can craft malicious image files that tr...

May 11, 2021
CVE-2021-29478
7.5

CVE-2021-29478 is an integer overflow vulnerability in Redis 6.2 that could allow attackers to corrupt heap memory and potentially achieve remote code...

May 4, 2021
CVE-2021-23840
7.5

This OpenSSL vulnerability involves integer overflow in cryptographic functions (EVP_CipherUpdate, EVP_EncryptUpdate, EVP_DecryptUpdate) when processi...

Feb 16, 2021
CVE-2020-27813
7.5

CVE-2020-27813 is an integer overflow vulnerability in websocket frame length handling that allows attackers to cause denial of service on HTTP server...

Dec 2, 2020
CVE-2021-27502
7.4

CVE-2021-27502 is an integer overflow vulnerability in Texas Instruments TI-RTOS when using HeapMem heap configuration. It allows attackers to trigger...

Nov 21, 2023
CVE-2021-27429
7.4

This CVE describes an integer overflow vulnerability in Texas Instruments TI-RTOS's HeapTrack_alloc function that can lead to heap corruption and pote...

Nov 20, 2023
CVE-2025-0005
7.3

An integer overflow vulnerability in the XOCL driver allows local attackers to cause denial of service or system crashes. This affects systems using A...

Nov 24, 2025
CVE-2025-23241
7.3

An integer overflow vulnerability in Intel 800 Series Ethernet kernel drivers allows authenticated local users to cause denial of service. This affect...

Aug 12, 2025
CVE-2025-49179
7.3

This integer overflow vulnerability in the X Record extension allows attackers to bypass length checks by manipulating request length calculations. Sy...

Jun 17, 2025
CVE-2025-49176
7.3

This vulnerability in the Big Requests extension allows attackers to bypass size limit checks through an integer overflow when request length is multi...

Jun 17, 2025
CVE-2024-36328
7.3

An integer overflow vulnerability in AMD's NPU (Neural Processing Unit) driver allows a local attacker to write out of bounds memory. This could lead ...

Apr 2, 2025
CVE-2024-11347
7.3

An integer overflow vulnerability in Lexmark printer PostScript interpreters allows attackers to execute arbitrary code with unprivileged user permiss...

Feb 13, 2025
CVE-2024-43495
7.3

CVE-2024-43495 is a remote code execution vulnerability in Windows libarchive that allows attackers to execute arbitrary code by exploiting integer ov...

Sep 10, 2024
CVE-2024-27101
7.3

An integer overflow vulnerability in SpiceDB's chunking helper causes permission-checking APIs to miss elements or panic when a resource has over 65,5...

Mar 1, 2024
CVE-2021-22680
7.3

This CVE describes an integer overflow vulnerability in NXP MQX RTOS memory allocation functions that can lead to arbitrary memory allocation. Attacke...

May 3, 2022
CVE-2021-27419
7.3

CVE-2021-27419 is an integer overflow vulnerability in uClibc-ng's malloc-simple functions that can lead to arbitrary memory allocation. This could ca...

May 3, 2022
CVE-2021-27425
7.3

CVE-2021-27425 is an integer wrap-around vulnerability in Mongoose-OS's mm_malloc function that can lead to arbitrary memory allocation. This could re...

May 3, 2022
CVE-2021-27431
7.3

This vulnerability in ARM CMSIS RTOS2 allows integer wrap-around in memory allocation functions, potentially leading to arbitrary memory allocation. T...

May 3, 2022
CVE-2021-27435
7.3

This vulnerability in ARM mbed OS 6.3.0 allows attackers to trigger integer wrap-around in memory allocation functions, potentially leading to arbitra...

May 3, 2022
CVE-2020-11263
7.3

CVE-2020-11263 is an integer overflow vulnerability in Qualcomm Snapdragon chipsets that occurs when improper checks are performed after memory addres...

Jan 3, 2022
CVE-2024-38019
7.2

This vulnerability in Microsoft Windows Performance Data Helper Library allows remote attackers to execute arbitrary code by sending specially crafted...

Jul 9, 2024
CVE-2023-36401
7.2

This vulnerability in Microsoft Remote Registry Service allows authenticated attackers to execute arbitrary code remotely on affected systems. It affe...

Nov 14, 2023
CVE-2025-24528
7.1

This vulnerability in MIT Kerberos 5 allows authenticated attackers to trigger an integer overflow in the kadmind daemon's log handling code, leading ...

Jan 16, 2026
CVE-2025-55067
7.1

The TLS4B ATG system suffers from a Year 2038 problem where Unix time values exceeding the 2038 epoch cause the system clock to reset to 1901, leading...

Oct 23, 2025
CVE-2022-49289
7.1

This CVE is an integer overflow vulnerability in the Linux kernel's access_ok() function that could allow attackers to bypass memory access restrictio...

Feb 26, 2025
CVE-2024-57261
7.1

This CVE describes an integer overflow vulnerability in barebox's memory allocation function request2size. Attackers could exploit this to cause heap ...

Feb 19, 2025
CVE-2024-57262
7.1

This vulnerability in barebox's ext4 filesystem implementation allows integer overflow when processing specially crafted ext4 filesystems with specifi...

Feb 19, 2025
CVE-2024-57254
7.1

An integer overflow vulnerability in Das U-Boot's squashfs filesystem parser allows attackers to cause memory corruption via specially crafted symlink...

Feb 18, 2025

About Integer Overflow (CWE-190)

The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.

Our database tracks 530 CVEs classified as CWE-190, with 104 rated critical and 306 rated high severity. The average CVSS score for Integer Overflow vulnerabilities is 7.8.

External reference: View CWE-190 on MITRE CWE →

Monitor Integer Overflow Vulnerabilities

Get alerted when new Integer Overflow CVEs affect your infrastructure.

Start Monitoring Free