Skip to content
Noroxi

CWE-682 · 122 records

Incorrect Calculation

CVEs in this class

122 records

  • Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connec

    HighCVSS 7.5Proof of conceptEPSS 57%

    lighttpd · lighttpdJun 11, 2022

  • A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, a

    CriticalCVSS 9.8No exploitEPSS 8%

    microsoft · research javascript cryptography libraryJul 10, 2018

  • A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    moodle · moodleMay 18, 2022

  • A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an imp

    CriticalCVSS 9.8No exploitEPSS 4%

    toktok · toxcoreDec 12, 2021

  • An issue in the oneflow.permute component of OneFlow-Inc.

    CriticalCVSS 9.8No exploitEPSS 1%

    oneflow · oneflowJun 6, 2024

  • CVE-2020-0221
    39Monitor

    Airbrush FW's scratch memory allocator is susceptible to numeric overflow.

    CriticalCVSS 9.8No exploitEPSS 0%

    google · androidMay 14, 2020

  • JIT miscompilation in the JavaScript: WebAssembly component

    CriticalCVSS 9.8No exploitEPSS 0%

    mozilla · firefoxJul 21, 2026

  • Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 7%

    microsoft · windows 10 1507Dec 12, 2023

  • CVE-2020-0022
    37Monitor

    In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation.

    HighCVSS 8.8Proof of conceptEPSS 6%

    google · androidFeb 13, 2020

  • Solana rBPF - Incorrect Calculation in sdiv instruction

    CriticalCVSS 9.1No exploitEPSS 3%

    solana · rbpfMay 9, 2022

  • PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verification

    CriticalCVSS 9.3No exploitEPSS 1%

    vbpf · prevailSep 2, 2026

  • PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verification

    CriticalCVSS 9.3No exploitEPSS 1%

    vbpf · prevailSep 2, 2026

  • In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbeh

    HighCVSS 8.8Proof of conceptEPSS 4%

    libexpat project · libexpatJan 1, 2022

  • CVE-2023-2163
    36Monitor

    Incorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalation

    HighCVSS 8.8Proof of conceptEPSS 4%

    linux · linux kernelSep 20, 2023

  • CVE-2017-8326
    36Monitor

    libimageworsener.a in ImageWorsener before 1.3.1 has "left shift cannot be represented in type int" undefined behavior issues, which might a

    HighCVSS 8.8No exploitEPSS 2%

    entropymine · imageworsenerApr 29, 2017

  • ZEBRA: Block Validator Undercounts Coinbase and P2SH Sigops

    CriticalCVSS 9.2No exploitEPSS 0%

    zfnd · zebradMay 8, 2026

  • ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pic

    HighCVSS 8.8No exploitEPSS 2%

    miniupnp project · ngiflibSep 16, 2019

  • STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.

    HighCVSS 8.8No exploitEPSS 2%

    stb project · stbApr 15, 2022

  • ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pi

    HighCVSS 8.8No exploitEPSS 1%

    miniupnp project · ngiflibSep 16, 2019

  • A remote code execution vulnerability in the Android media framework (libmpeg2).

    HighCVSS 8.8No exploitEPSS 1%

    google · androidDec 6, 2017

  • CVE-2019-5853
    35Monitor

    Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corr

    HighCVSS 8.8No exploitEPSS 1%

    google · chromeNov 25, 2019

  • PREVAIL: ALU32 pointer arithmetic accepted without is64 gate — verifier emits false PASS for pointer-corrupting programs

    HighCVSS 8.8No exploitEPSS 1%

    vbpf · prevailSep 2, 2026

  • The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data stream

    HighCVSS 8.8No exploitEPSS 0%

    xen · xenAug 24, 2017

  • CVE-2025-5372
    35Monitor

    Libssh: incorrect return code handling in ssh_kdf() in libssh

    HighCVSS 8.8No exploitEPSS 0%

    libssh · libsshJul 4, 2025

  • Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors

    HighCVSS 8.8No exploitEPSS 0%

    xen · xenAug 24, 2017

All vulnerability classes