CWE-682 · 122 записей
Incorrect Calculation
CVE этого класса
122 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2022-30780Proof of concept | Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because conneclighttpd · lighttpd · CWE-682 | Высокая7,5 | — | 56,9 % | 11 июн. 2022 г. |
41В плане | CVE-2018-8319Эксплойта нет | A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, amicrosoft · research javascript cryptography library · CWE-682 | Критическая9,8 | — | 7,5 % | 10 июл. 2018 г. |
41В плане | CVE-2022-30600Proof of concept | A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.moodle · moodle · CWE-682 | Критическая9,8 | — | 5,1 % | 18 мая 2022 г. |
40В плане | CVE-2021-44847Эксплойта нет | A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an imptoktok · toxcore · CWE-682 | Критическая9,8 | — | 3,8 % | 12 дек. 2021 г. |
39Наблюдать | CVE-2024-36736Эксплойта нет | An issue in the oneflow.permute component of OneFlow-Inc.oneflow · oneflow · CWE-682 | Критическая9,8 | — | 0,6 % | 6 июн. 2024 г. |
39Наблюдать | CVE-2020-0221Эксплойта нет | Airbrush FW's scratch memory allocator is susceptible to numeric overflow.google · android · CWE-682 | Критическая9,8 | — | 0,5 % | 14 мая 2020 г. |
39Наблюдать | CVE-2026-16363Эксплойта нет | JIT miscompilation in the JavaScript: WebAssembly componentmozilla · firefox · CWE-682 | Критическая9,8 | — | 0,4 % | 21 июл. 2026 г. |
37Наблюдать | CVE-2023-35641Эксплойта нет | Internet Connection Sharing (ICS) Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-682 | Высокая8,8 | — | 7,2 % | 12 дек. 2023 г. |
37Наблюдать | CVE-2020-0022Proof of concept | In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation.google · android · CWE-682 | Высокая8,8 | — | 6,1 % | 13 февр. 2020 г. |
37Наблюдать | CVE-2022-23066Эксплойта нет | Solana rBPF - Incorrect Calculation in sdiv instructionsolana · rbpf · CWE-682 | Критическая9,1 | — | 2,5 % | 9 мая 2022 г. |
37Наблюдать | CVE-2026-53670Эксплойта нет | PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verificationvbpf · prevail · CWE-682 | Критическая9,3 | — | 0,5 % | 2 сент. 2026 г. |
37Наблюдать | CVE-2026-53671Эксплойта нет | PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verificationvbpf · prevail · CWE-682 | Критическая9,3 | — | 0,5 % | 2 сент. 2026 г. |
36Наблюдать | CVE-2021-45960Proof of concept | In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehlibexpat project · libexpat · CWE-682 | Высокая8,8 | — | 4,2 % | 1 янв. 2022 г. |
36Наблюдать | CVE-2023-2163Proof of concept | Incorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalationlinux · linux kernel · CWE-682 | Высокая8,8 | — | 3,7 % | 20 сент. 2023 г. |
36Наблюдать | CVE-2017-8326Эксплойта нет | libimageworsener.a in ImageWorsener before 1.3.1 has "left shift cannot be represented in type int" undefined behavior issues, which might aentropymine · imageworsener · CWE-682 | Высокая8,8 | — | 2,4 % | 29 апр. 2017 г. |
36Наблюдать | CVE-2026-44498Эксплойта нет | ZEBRA: Block Validator Undercounts Coinbase and P2SH Sigopszfnd · zebrad · CWE-682 | Критическая9,2 | — | 0,4 % | 8 мая 2026 г. |
35Наблюдать | CVE-2019-16346Эксплойта нет | ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small picminiupnp project · ngiflib · CWE-682 | Высокая8,8 | — | 1,6 % | 16 сент. 2019 г. |
35Наблюдать | CVE-2022-28048Эксплойта нет | STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.stb project · stb · CWE-682 | Высокая8,8 | — | 1,6 % | 15 апр. 2022 г. |
35Наблюдать | CVE-2019-16347Эксплойта нет | ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small piminiupnp project · ngiflib · CWE-682 | Высокая8,8 | — | 1,5 % | 16 сент. 2019 г. |
35Наблюдать | CVE-2017-13151Эксплойта нет | A remote code execution vulnerability in the Android media framework (libmpeg2).google · android · CWE-682 | Высокая8,8 | — | 1,4 % | 6 дек. 2017 г. |
35Наблюдать | CVE-2019-5853Эксплойта нет | Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corrgoogle · chrome · CWE-682 | Высокая8,8 | — | 1,0 % | 25 нояб. 2019 г. |
35Наблюдать | CVE-2026-53706Эксплойта нет | PREVAIL: ALU32 pointer arithmetic accepted without is64 gate — verifier emits false PASS for pointer-corrupting programsvbpf · prevail · CWE-682 | Высокая8,8 | — | 0,5 % | 2 сент. 2026 г. |
35Наблюдать | CVE-2017-12134Эксплойта нет | The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streamxen · xen · CWE-682 | Высокая8,8 | — | 0,5 % | 24 авг. 2017 г. |
35Наблюдать | CVE-2025-5372Эксплойта нет | Libssh: incorrect return code handling in ssh_kdf() in libsshlibssh · libssh · CWE-682 | Высокая8,8 | — | 0,5 % | 4 июл. 2025 г. |
35Наблюдать | CVE-2017-12135Эксплойта нет | Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectorsxen · xen · CWE-682 | Высокая8,8 | — | 0,5 % | 24 авг. 2017 г. |
- CVE-2022-3078047В плане
Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connec
ВысокаяCVSS 7,5Proof of conceptEPSS 57 %lighttpd · lighttpd11 июн. 2022 г.
- CVE-2018-831941В плане
A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, a
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %microsoft · research javascript cryptography library10 июл. 2018 г.
- CVE-2022-3060041В плане
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %moodle · moodle18 мая 2022 г.
- CVE-2021-4484740В плане
A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an imp
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %toktok · toxcore12 дек. 2021 г.
- CVE-2024-3673639Наблюдать
An issue in the oneflow.permute component of OneFlow-Inc.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oneflow · oneflow6 июн. 2024 г.
- CVE-2020-022139Наблюдать
Airbrush FW's scratch memory allocator is susceptible to numeric overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %google · android14 мая 2020 г.
- CVE-2026-1636339Наблюдать
JIT miscompilation in the JavaScript: WebAssembly component
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %mozilla · firefox21 июл. 2026 г.
- CVE-2023-3564137Наблюдать
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 7 %microsoft · windows 10 150712 дек. 2023 г.
- CVE-2020-002237Наблюдать
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation.
ВысокаяCVSS 8,8Proof of conceptEPSS 6 %google · android13 февр. 2020 г.
- CVE-2022-2306637Наблюдать
Solana rBPF - Incorrect Calculation in sdiv instruction
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %solana · rbpf9 мая 2022 г.
- CVE-2026-5367037Наблюдать
PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verification
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %vbpf · prevail2 сент. 2026 г.
- CVE-2026-5367137Наблюдать
PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verification
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %vbpf · prevail2 сент. 2026 г.
- CVE-2021-4596036Наблюдать
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbeh
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %libexpat project · libexpat1 янв. 2022 г.
- CVE-2023-216336Наблюдать
Incorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalation
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %linux · linux kernel20 сент. 2023 г.
- CVE-2017-832636Наблюдать
libimageworsener.a in ImageWorsener before 1.3.1 has "left shift cannot be represented in type int" undefined behavior issues, which might a
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %entropymine · imageworsener29 апр. 2017 г.
- CVE-2026-4449836Наблюдать
ZEBRA: Block Validator Undercounts Coinbase and P2SH Sigops
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %zfnd · zebrad8 мая 2026 г.
- CVE-2019-1634635Наблюдать
ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pic
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %miniupnp project · ngiflib16 сент. 2019 г.
- CVE-2022-2804835Наблюдать
STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %stb project · stb15 апр. 2022 г.
- CVE-2019-1634735Наблюдать
ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %miniupnp project · ngiflib16 сент. 2019 г.
- CVE-2017-1315135Наблюдать
A remote code execution vulnerability in the Android media framework (libmpeg2).
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %google · android6 дек. 2017 г.
- CVE-2019-585335Наблюдать
Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corr
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %google · chrome25 нояб. 2019 г.
- CVE-2026-5370635Наблюдать
PREVAIL: ALU32 pointer arithmetic accepted without is64 gate — verifier emits false PASS for pointer-corrupting programs
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %vbpf · prevail2 сент. 2026 г.
- CVE-2017-1213435Наблюдать
The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data stream
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %xen · xen24 авг. 2017 г.
- CVE-2025-537235Наблюдать
Libssh: incorrect return code handling in ssh_kdf() in libssh
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %libssh · libssh4 июл. 2025 г.
- CVE-2017-1213535Наблюдать
Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %xen · xen24 авг. 2017 г.