CWE-682 · 122 records
Incorrect Calculation
CVEs in this class
122 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2022-30780Proof of concept | Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because conneclighttpd · lighttpd · CWE-682 | High7.5 | — | 56.9% | Jun 11, 2022 |
41Plan | CVE-2018-8319No exploit | A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, amicrosoft · research javascript cryptography library · CWE-682 | Critical9.8 | — | 7.5% | Jul 10, 2018 |
41Plan | CVE-2022-30600Proof of concept | A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.moodle · moodle · CWE-682 | Critical9.8 | — | 5.1% | May 18, 2022 |
40Plan | CVE-2021-44847No exploit | A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an imptoktok · toxcore · CWE-682 | Critical9.8 | — | 3.8% | Dec 12, 2021 |
39Monitor | CVE-2024-36736No exploit | An issue in the oneflow.permute component of OneFlow-Inc.oneflow · oneflow · CWE-682 | Critical9.8 | — | 0.6% | Jun 6, 2024 |
39Monitor | CVE-2020-0221No exploit | Airbrush FW's scratch memory allocator is susceptible to numeric overflow.google · android · CWE-682 | Critical9.8 | — | 0.5% | May 14, 2020 |
39Monitor | CVE-2026-16363No exploit | JIT miscompilation in the JavaScript: WebAssembly componentmozilla · firefox · CWE-682 | Critical9.8 | — | 0.4% | Jul 21, 2026 |
37Monitor | CVE-2023-35641No exploit | Internet Connection Sharing (ICS) Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-682 | High8.8 | — | 7.2% | Dec 12, 2023 |
37Monitor | CVE-2020-0022Proof of concept | In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation.google · android · CWE-682 | High8.8 | — | 6.1% | Feb 13, 2020 |
37Monitor | CVE-2022-23066No exploit | Solana rBPF - Incorrect Calculation in sdiv instructionsolana · rbpf · CWE-682 | Critical9.1 | — | 2.5% | May 9, 2022 |
37Monitor | CVE-2026-53670No exploit | PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verificationvbpf · prevail · CWE-682 | Critical9.3 | — | 0.5% | Sep 2, 2026 |
37Monitor | CVE-2026-53671No exploit | PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verificationvbpf · prevail · CWE-682 | Critical9.3 | — | 0.5% | Sep 2, 2026 |
36Monitor | CVE-2021-45960Proof of concept | In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehlibexpat project · libexpat · CWE-682 | High8.8 | — | 4.2% | Jan 1, 2022 |
36Monitor | CVE-2023-2163Proof of concept | Incorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalationlinux · linux kernel · CWE-682 | High8.8 | — | 3.7% | Sep 20, 2023 |
36Monitor | CVE-2017-8326No exploit | libimageworsener.a in ImageWorsener before 1.3.1 has "left shift cannot be represented in type int" undefined behavior issues, which might aentropymine · imageworsener · CWE-682 | High8.8 | — | 2.4% | Apr 29, 2017 |
36Monitor | CVE-2026-44498No exploit | ZEBRA: Block Validator Undercounts Coinbase and P2SH Sigopszfnd · zebrad · CWE-682 | Critical9.2 | — | 0.4% | May 8, 2026 |
35Monitor | CVE-2019-16346No exploit | ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small picminiupnp project · ngiflib · CWE-682 | High8.8 | — | 1.6% | Sep 16, 2019 |
35Monitor | CVE-2022-28048No exploit | STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.stb project · stb · CWE-682 | High8.8 | — | 1.6% | Apr 15, 2022 |
35Monitor | CVE-2019-16347No exploit | ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small piminiupnp project · ngiflib · CWE-682 | High8.8 | — | 1.5% | Sep 16, 2019 |
35Monitor | CVE-2017-13151No exploit | A remote code execution vulnerability in the Android media framework (libmpeg2).google · android · CWE-682 | High8.8 | — | 1.4% | Dec 6, 2017 |
35Monitor | CVE-2019-5853No exploit | Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corrgoogle · chrome · CWE-682 | High8.8 | — | 1.0% | Nov 25, 2019 |
35Monitor | CVE-2026-53706No exploit | PREVAIL: ALU32 pointer arithmetic accepted without is64 gate — verifier emits false PASS for pointer-corrupting programsvbpf · prevail · CWE-682 | High8.8 | — | 0.5% | Sep 2, 2026 |
35Monitor | CVE-2017-12134No exploit | The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streamxen · xen · CWE-682 | High8.8 | — | 0.5% | Aug 24, 2017 |
35Monitor | CVE-2025-5372No exploit | Libssh: incorrect return code handling in ssh_kdf() in libsshlibssh · libssh · CWE-682 | High8.8 | — | 0.5% | Jul 4, 2025 |
35Monitor | CVE-2017-12135No exploit | Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectorsxen · xen · CWE-682 | High8.8 | — | 0.5% | Aug 24, 2017 |
- CVE-2022-3078047Plan
Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connec
HighCVSS 7.5Proof of conceptEPSS 57%lighttpd · lighttpdJun 11, 2022
- CVE-2018-831941Plan
A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, a
CriticalCVSS 9.8No exploitEPSS 8%microsoft · research javascript cryptography libraryJul 10, 2018
- CVE-2022-3060041Plan
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
CriticalCVSS 9.8Proof of conceptEPSS 5%moodle · moodleMay 18, 2022
- CVE-2021-4484740Plan
A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an imp
CriticalCVSS 9.8No exploitEPSS 4%toktok · toxcoreDec 12, 2021
- CVE-2024-3673639Monitor
An issue in the oneflow.permute component of OneFlow-Inc.
CriticalCVSS 9.8No exploitEPSS 1%oneflow · oneflowJun 6, 2024
- CVE-2020-022139Monitor
Airbrush FW's scratch memory allocator is susceptible to numeric overflow.
CriticalCVSS 9.8No exploitEPSS 0%google · androidMay 14, 2020
- CVE-2026-1636339Monitor
JIT miscompilation in the JavaScript: WebAssembly component
CriticalCVSS 9.8No exploitEPSS 0%mozilla · firefoxJul 21, 2026
- CVE-2023-3564137Monitor
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 7%microsoft · windows 10 1507Dec 12, 2023
- CVE-2020-002237Monitor
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation.
HighCVSS 8.8Proof of conceptEPSS 6%google · androidFeb 13, 2020
- CVE-2022-2306637Monitor
Solana rBPF - Incorrect Calculation in sdiv instruction
CriticalCVSS 9.1No exploitEPSS 3%solana · rbpfMay 9, 2022
- CVE-2026-5367037Monitor
PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verification
CriticalCVSS 9.3No exploitEPSS 1%vbpf · prevailSep 2, 2026
- CVE-2026-5367137Monitor
PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verification
CriticalCVSS 9.3No exploitEPSS 1%vbpf · prevailSep 2, 2026
- CVE-2021-4596036Monitor
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbeh
HighCVSS 8.8Proof of conceptEPSS 4%libexpat project · libexpatJan 1, 2022
- CVE-2023-216336Monitor
Incorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalation
HighCVSS 8.8Proof of conceptEPSS 4%linux · linux kernelSep 20, 2023
- CVE-2017-832636Monitor
libimageworsener.a in ImageWorsener before 1.3.1 has "left shift cannot be represented in type int" undefined behavior issues, which might a
HighCVSS 8.8No exploitEPSS 2%entropymine · imageworsenerApr 29, 2017
- CVE-2026-4449836Monitor
ZEBRA: Block Validator Undercounts Coinbase and P2SH Sigops
CriticalCVSS 9.2No exploitEPSS 0%zfnd · zebradMay 8, 2026
- CVE-2019-1634635Monitor
ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pic
HighCVSS 8.8No exploitEPSS 2%miniupnp project · ngiflibSep 16, 2019
- CVE-2022-2804835Monitor
STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
HighCVSS 8.8No exploitEPSS 2%stb project · stbApr 15, 2022
- CVE-2019-1634735Monitor
ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pi
HighCVSS 8.8No exploitEPSS 1%miniupnp project · ngiflibSep 16, 2019
- CVE-2017-1315135Monitor
A remote code execution vulnerability in the Android media framework (libmpeg2).
HighCVSS 8.8No exploitEPSS 1%google · androidDec 6, 2017
- CVE-2019-585335Monitor
Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corr
HighCVSS 8.8No exploitEPSS 1%google · chromeNov 25, 2019
- CVE-2026-5370635Monitor
PREVAIL: ALU32 pointer arithmetic accepted without is64 gate — verifier emits false PASS for pointer-corrupting programs
HighCVSS 8.8No exploitEPSS 1%vbpf · prevailSep 2, 2026
- CVE-2017-1213435Monitor
The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data stream
HighCVSS 8.8No exploitEPSS 0%xen · xenAug 24, 2017
- CVE-2025-537235Monitor
Libssh: incorrect return code handling in ssh_kdf() in libssh
HighCVSS 8.8No exploitEPSS 0%libssh · libsshJul 4, 2025
- CVE-2017-1213535Monitor
Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors
HighCVSS 8.8No exploitEPSS 0%xen · xenAug 24, 2017