CWE-190: Integer Overflow
The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.
Yearly Trend
Top Affected Vendors
All Integer Overflow CVEs (530)
This CVE describes an integer overflow vulnerability in Das U-Boot's squashfs filesystem handling. When processing a specially crafted squashfs filesy...
Feb 18, 2025Integer overflow vulnerabilities in Das U-Boot's memory allocation functions allow attackers to cause heap corruption via specially crafted squashfs f...
Feb 18, 2025This vulnerability in lrzsz (a file transfer tool) allows information leakage to the receiving side due to an integer overflow in the zsdata function....
Jun 2, 2021This CVE describes an integer overflow vulnerability in TensorFlow's TFLite component. An attacker can craft a malicious machine learning model that c...
May 14, 2021This CVE describes an integer overflow vulnerability in Redis that allows authenticated users to execute specially crafted Lua scripts, potentially le...
Oct 3, 2025This CVE describes integer overflow vulnerabilities in GTKWave's VZT file parser that can lead to memory corruption when processing specially crafted ...
Jan 8, 2024This CVE describes integer overflow vulnerabilities in GTKWave's VZT file parser that can lead to memory corruption when processing specially crafted ...
Jan 8, 2024An integer overflow vulnerability in GTKWave's FST file parser allows memory corruption when processing malicious .fst files. This affects users who o...
Jan 8, 2024An integer overflow vulnerability in GTKWave's FST_BL_GEOM parser allows memory corruption when processing malicious .fst files. This affects users wh...
Jan 8, 2024This vulnerability allows an attacker to gain SYSTEM-level privileges on Windows systems by exploiting an integer overflow in the PPPoE driver. It aff...
Mar 14, 2023This CVE describes an integer overflow vulnerability in libexpat's doContent function that can lead to buffer overflow during XML parsing. Attackers c...
Jan 30, 2026This CVE describes an integer overflow vulnerability (CWE-190) in Qualcomm partition handling that could allow memory corruption when calculating offs...
Feb 2, 2026CVE-2024-26184 is a Secure Boot security feature bypass vulnerability that allows attackers to circumvent Secure Boot protections on affected systems....
Jul 9, 2024This vulnerability in the Windows Mobile Broadband Driver allows an attacker to execute arbitrary code remotely by sending specially crafted packets t...
May 14, 2024This vulnerability in the Windows Mobile Broadband Driver allows an attacker to execute arbitrary code remotely by sending specially crafted packets t...
May 14, 2024This CVE describes an integer overflow vulnerability in dpe (likely a MediaTek component) that could lead to memory corruption. An attacker with Syste...
Jan 6, 2026CVE-2025-20807 is an integer overflow vulnerability in dpe that leads to out-of-bounds write, allowing local privilege escalation. Attackers with Syst...
Jan 6, 2026This CVE describes an integer overflow vulnerability in the lwis_test_register_io function of lwis_device_test.c that leads to an out-of-bounds write....
Sep 4, 2025This CVE describes an integer overflow vulnerability in Huawei's partition module where insufficient data length verification allows attackers to caus...
Aug 6, 2025This vulnerability allows local privilege escalation on Android devices through an integer overflow in the RIL component. Attackers with system execut...
Dec 5, 2024This vulnerability allows attackers to bypass security features in Windows Resume Extensible Firmware Interface (Resume EFI) during system resume oper...
Oct 8, 2024This CVE describes a memory corruption vulnerability in Qualcomm components where sending excessive scan frequency lists or channels from user space c...
Jun 3, 2024This CVE describes an integer overflow vulnerability in Android's fdt.c that could allow local privilege escalation. An attacker could exploit this to...
Mar 24, 2023This CVE describes an integer overflow vulnerability in MediaTek battery management components that could allow local privilege escalation. Attackers ...
Apr 1, 2024This vulnerability in vsftpd allows a remote authenticated attacker to cause a denial of service (DoS) by sending a specially crafted STAT command tha...
Jan 14, 2026A heap buffer overflow vulnerability in PHP's array_merge() function allows memory corruption when merging large packed arrays. This affects PHP serve...
Dec 27, 2025An integer overflow vulnerability in the Bluetooth Host stack's bt_br_acl_recv routine allows attackers to trigger memory corruption when processing B...
Dec 15, 2025This vulnerability in GLib's GIO component allows heap buffer overflow and denial-of-service via integer overflow when processing malicious file attri...
Dec 11, 2025An integer overflow vulnerability in FreeImage's PSD parser allows attackers to cause Denial of Service by supplying a specially crafted PSD file. Thi...
Dec 10, 2025CVE-2025-63938 is an integer overflow vulnerability in Tinyproxy's strip_return_port() function that could allow remote attackers to cause a denial of...
Nov 26, 2025This vulnerability in the Russh SSH library allows integer overflow when processing SSH channel window adjust messages, potentially causing a denial-o...
Aug 5, 2025A vulnerability in nbdkit's blocksize filter allows denial of service when clients request block status information for excessively large data ranges....
Jun 9, 2025A signed 64-bit integer overflow vulnerability in iputils ping allows denial of service through crafted ICMP Echo Reply packets. This can cause ping t...
May 5, 2025This CVE describes an integer overflow vulnerability in multiple Apple operating systems that could allow an attacker on the local network to cause a ...
Apr 29, 2025This vulnerability allows a local attacker to execute arbitrary code in pre-installed apps on OpenHarmony devices through an integer overflow. It affe...
Apr 7, 2025This CVE describes an integer overflow vulnerability in the ihevcd_allocate_dynamic_bufs function of Android's HEVC decoder. An attacker could trigger...
Nov 27, 2024CVE-2018-9482 is an integer overflow vulnerability in Android's Bluetooth service that allows local attackers to read memory beyond intended boundarie...
Nov 20, 2024CVE-2018-9348 is an integer overflow vulnerability in Android's SMF parser that could allow remote attackers to cause denial of service through resour...
Nov 19, 2024This vulnerability in Redis allows authenticated users to execute specially crafted LUA scripts that can read out-of-bounds memory or crash the server...
Oct 3, 2025CVE-2024-38805 is an integer overflow vulnerability in EDK2 BIOS/UEFI firmware that can be triggered via network packets. Successful exploitation coul...
Aug 12, 2025FFmpeg versions containing the vulnerable DXA demuxer in libavformat have an integer overflow vulnerability that can cause denial-of-service (DoS) or ...
Jan 3, 2025CVE-2024-36617 is an integer overflow vulnerability in FFmpeg's CAF decoder that could allow attackers to cause denial of service or potentially execu...
Nov 29, 2024This vulnerability in Xpdf allows attackers to cause integer overflow and divide-by-zero errors by providing malicious PDF files with very large coord...
Aug 15, 2024An integer wraparound vulnerability in PostgreSQL's libpq client library allows attackers to cause undersized memory allocations leading to out-of-bou...
Nov 13, 2025A buffer-underflow vulnerability in GLib's GVariant parser allows remote attackers to cause heap corruption by sending maliciously crafted input strin...
Dec 10, 2025An integer overflow vulnerability in AMD Graphics drivers allows attackers to bypass size checks, potentially causing denial of service. This affects ...
Feb 11, 2026CVE-2026-21354 is an integer overflow vulnerability in Adobe DNG SDK versions 1.7.1 2410 and earlier. Attackers can craft malicious DNG files that cau...
Feb 10, 2026CVE-2025-64894 is an integer overflow vulnerability in DNG SDK versions 1.7.0 and earlier that allows attackers to cause denial-of-service by tricking...
Dec 9, 2025This CVE describes an integer overflow vulnerability in the GNSS driver that could lead to an out-of-bounds read. If exploited by a malicious actor wi...
Oct 14, 2025This CVE-2023-53661 is an integer overflow vulnerability in the bnxt_get_nvram_directory() function of the Linux kernel's Broadcom NetXtreme Ethernet ...
Oct 7, 2025About Integer Overflow (CWE-190)
The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes the result will always be larger than the original value.
Our database tracks 530 CVEs classified as CWE-190, with 104 rated critical and 306 rated high severity. The average CVSS score for Integer Overflow vulnerabilities is 7.8.
External reference: View CWE-190 on MITRE CWE →
Monitor Integer Overflow Vulnerabilities
Get alerted when new Integer Overflow CVEs affect your infrastructure.
Start Monitoring Free