CWE-190 · 3,189 records
Integer Overflow or Wraparound
CVEs in this class
3,193 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
89Now | CVE-2013-2729Weaponized | Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitadobe · acrobat · CWE-190 | Critical9.8 | KEV | 66.6% | May 16, 2013 |
85Now | CVE-2015-8651Weaponized | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on adobe · air sdk · CWE-190 | High8.8 | KEV | 67.7% | Dec 28, 2015 |
84Now | CVE-2021-30860Weaponized | An integer overflow was addressed with improved input validation.apple · ipados · CWE-190 | High7.8 | KEV | 76.0% | Aug 24, 2021 |
83Now | CVE-2018-6065Weaponized | Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3google · chrome · CWE-190 | High8.8 | KEV | 60.3% | Nov 14, 2018 |
76This week | CVE-2023-32434Weaponized | An integer overflow was addressed with improved input validation.apple · ipados · CWE-190 | High7.8 | KEV | 51.5% | Jun 23, 2023 |
73This week | CVE-2011-1823Weaponized | The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows google · android · CWE-190 | High7.8 | KEV | 41.4% | Jun 9, 2011 |
73This week | CVE-2023-6345Weaponized | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potegoogle · chrome · CWE-190 | Critical9.6 | KEV | 16.5% | Nov 29, 2023 |
71This week | CVE-2022-0185Weaponized | A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux linux · linux kernel · CWE-190 | High8.4 | KEV | 25.2% | Feb 11, 2022 |
71This week | CVE-2012-5054Weaponized | Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execadobe · flash player · CWE-190 | High8.8 | KEV | 21.2% | Sep 24, 2012 |
71This week | CVE-2016-1010Weaponized | Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577adobe · flash player · CWE-190 | High8.8 | KEV | 19.3% | Mar 12, 2016 |
70This week | CVE-2023-2136Weaponized | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potegoogle · chrome · CWE-190 | Critical9.6 | KEV | 5.7% | Apr 19, 2023 |
66This week | CVE-2021-30663Weaponized | An integer overflow was addressed with improved input validation.apple · safari · CWE-190 | High8.8 | KEV | 3.5% | Sep 8, 2021 |
65This week | CVE-2018-14634Weaponized | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function.linux · linux kernel · CWE-190 | High7.8 | KEV | 14.7% | Sep 25, 2018 |
64This week | CVE-2014-0569Weaponized | Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on adobe · flash player · CWE-190 | Critical9.3 | — | 91.3% | Oct 15, 2014 |
64This week | CVE-2023-21716Proof of concept | Microsoft Word Remote Code Execution Vulnerabilitymicrosoft · office · CWE-190 | Critical9.8 | — | 84.8% | Feb 14, 2023 |
64This week | CVE-2025-48595Weaponized | In multiple locations, there is a possible way to achieve code execution due to an integer overflow.google · android · CWE-190 | High8.4 | KEV | 1.7% | Jun 1, 2026 |
63This week | CVE-2024-38080Weaponized | Windows Hyper-V Elevation of Privilege Vulnerabilitymicrosoft · windows 11 21h2 · CWE-190 | High7.8 | KEV | 7.1% | Jul 9, 2024 |
63This week | CVE-2021-30952Weaponized | An integer overflow was addressed with improved input validation.apple · safari · CWE-190 | High7.8 | KEV | 7.0% | Aug 24, 2021 |
63This week | CVE-2023-21823Weaponized | Windows Graphics Component Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-190 | High7.8 | KEV | 5.6% | Feb 14, 2023 |
62This week | CVE-2013-2596Weaponized | Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Alinux · linux kernel · CWE-190 | High7.8 | KEV | 3.2% | Apr 12, 2013 |
61This week | CVE-2019-11072No exploit | lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) orlighttpd · lighttpd · CWE-190 | Critical9.8 | — | 73.8% | Apr 10, 2019 |
61This week | CVE-2024-49112Proof of concept | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-190 | Critical9.8 | — | 71.9% | Dec 11, 2024 |
61This week | CVE-2026-21385Weaponized | Integer Overflow or Wraparound in Graphicsqualcomm · sm7675p firmware · CWE-190 | High7.8 | KEV | 1.2% | Mar 2, 2026 |
61This week | CVE-2023-33107Weaponized | Integer Overflow or Wraparound in Graphics Linuxqualcomm · 315 5g iot modem firmware · CWE-190 | High7.8 | KEV | 0.9% | Dec 4, 2023 |
60This week | CVE-2019-11477Proof of concept | Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segslinux · linux kernel · CWE-190 | High7.5 | — | 98.7% | Jun 18, 2019 |
- CVE-2013-272989Now
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbit
CriticalCVSS 9.8KEVWeaponizedEPSS 67%adobe · acrobatMay 16, 2013
- CVE-2015-865185Now
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
HighCVSS 8.8KEVWeaponizedEPSS 68%adobe · air sdkDec 28, 2015
- CVE-2021-3086084Now
An integer overflow was addressed with improved input validation.
HighCVSS 7.8KEVWeaponizedEPSS 76%apple · ipadosAug 24, 2021
- CVE-2018-606583Now
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3
HighCVSS 8.8KEVWeaponizedEPSS 60%google · chromeNov 14, 2018
- CVE-2023-3243476This week
An integer overflow was addressed with improved input validation.
HighCVSS 7.8KEVWeaponizedEPSS 52%apple · ipadosJun 23, 2023
- CVE-2011-182373This week
The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows
HighCVSS 7.8KEVWeaponizedEPSS 41%google · androidJun 9, 2011
- CVE-2023-634573This week
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to pote
CriticalCVSS 9.6KEVWeaponizedEPSS 16%google · chromeNov 29, 2023
- CVE-2022-018571This week
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux
HighCVSS 8.4KEVWeaponizedEPSS 25%linux · linux kernelFeb 11, 2022
- CVE-2012-505471This week
Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to exec
HighCVSS 8.8KEVWeaponizedEPSS 21%adobe · flash playerSep 24, 2012
- CVE-2016-101071This week
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577
HighCVSS 8.8KEVWeaponizedEPSS 19%adobe · flash playerMar 12, 2016
- CVE-2023-213670This week
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to pote
CriticalCVSS 9.6KEVWeaponizedEPSS 6%google · chromeApr 19, 2023
- CVE-2021-3066366This week
An integer overflow was addressed with improved input validation.
HighCVSS 8.8KEVWeaponizedEPSS 3%apple · safariSep 8, 2021
- CVE-2018-1463465This week
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function.
HighCVSS 7.8KEVWeaponizedEPSS 15%linux · linux kernelSep 25, 2018
- CVE-2014-056964This week
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on
CriticalCVSS 9.3WeaponizedEPSS 91%adobe · flash playerOct 15, 2014
- CVE-2023-2171664This week
Microsoft Word Remote Code Execution Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 85%microsoft · officeFeb 14, 2023
- CVE-2025-4859564This week
In multiple locations, there is a possible way to achieve code execution due to an integer overflow.
HighCVSS 8.4KEVWeaponizedEPSS 2%google · androidJun 1, 2026
- CVE-2024-3808063This week
Windows Hyper-V Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 7%microsoft · windows 11 21h2Jul 9, 2024
- CVE-2021-3095263This week
An integer overflow was addressed with improved input validation.
HighCVSS 7.8KEVWeaponizedEPSS 7%apple · safariAug 24, 2021
- CVE-2023-2182363This week
Windows Graphics Component Remote Code Execution Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 6%microsoft · windows 10 1507Feb 14, 2023
- CVE-2013-259662This week
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of A
HighCVSS 7.8KEVWeaponizedEPSS 3%linux · linux kernelApr 12, 2013
- CVE-2019-1107261This week
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or
CriticalCVSS 9.8No exploitEPSS 74%lighttpd · lighttpdApr 10, 2019
- CVE-2024-4911261This week
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 72%microsoft · windows 10 1507Dec 11, 2024
- CVE-2026-2138561This week
Integer Overflow or Wraparound in Graphics
HighCVSS 7.8KEVWeaponizedEPSS 1%qualcomm · sm7675p firmwareMar 2, 2026
- CVE-2023-3310761This week
Integer Overflow or Wraparound in Graphics Linux
HighCVSS 7.8KEVWeaponizedEPSS 1%qualcomm · 315 5g iot modem firmwareDec 4, 2023
- CVE-2019-1147760This week
Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segs
HighCVSS 7.5Proof of conceptEPSS 99%linux · linux kernelJun 18, 2019