CWE-190: Integer Overflow or Wraparound — known CVE vulnerabilities
CVEs classified under CWE-190 (Integer Overflow or Wraparound), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-4689 — CVSS 10.0 (critical): Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149…
CVE-2026-24814: Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is associated with…
CVE-2025-64721 — CVSS 10.0 (critical): Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.6 and below, the…
CVE-2015-5108 — CVSS 10.0 (critical): Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before…
CVE-2015-5097 — CVSS 10.0 (critical): Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before…
CVE-2013-2555 — CVSS 10.0 (critical): Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x…
CVE-2012-5143 — CVSS 10.0 (critical): Integer overflow in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified…
CVE-2012-5835 — CVSS 10.0 (critical): Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0…
CVE-2010-3254 — CVSS 10.0 (critical): The WebSockets implementation in Google Chrome before 6.0.472.53 does not properly handle integer values, which allows remote attackers to…
CVE-2010-1233 — CVSS 10.0 (critical): Multiple integer overflows in Google Chrome before 4.1.249.1036 allow remote attackers to have an unspecified impact via vectors involving…
CVE-2008-2663 — CVSS 10.0 (critical): Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and…
CVE-2020-27484 — CVSS 9.9 (critical): Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow. The component is: ConnectIQ TVM. The attack vector is: To exploit the…
CVE-2026-17160 — CVSS 9.8 (critical): IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during…
CVE-2026-16917 — CVSS 9.8 (critical): IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow.
CVE-2026-16834 — CVSS 9.8 (critical): IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer underflow.
CVE-2026-74964 — CVSS 9.8 (critical): Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird…
CVE-2026-73193 — CVSS 9.8 (critical): DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size…
CVE-2026-19001 — CVSS 9.8 (critical): The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long…
CVE-2026-64774 — CVSS 9.8 (critical): An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and…
CVE-2026-64694 — CVSS 9.8 (critical): An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS…
CVE-2026-43769 — CVSS 9.8 (critical): An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and…
CVE-2026-43764 — CVSS 9.8 (critical): An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS…
CVE-2026-16280 — CVSS 9.8 (critical): An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs…
CVE-2026-16408 — CVSS 9.8 (critical): Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16402 — CVSS 9.8 (critical): Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16395 — CVSS 9.8 (critical): Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16389 — CVSS 9.8 (critical): Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and…
CVE-2026-16369 — CVSS 9.8 (critical): Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird…
CVE-2026-57433 — CVSS 9.8 (critical): Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common…
CVE-2026-14544 — CVSS 9.8 (critical): A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a…
CVE-2026-46039 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length check Fix potential…
CVE-2026-48691 — CVSS 9.8 (critical): FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the…
CVE-2026-8631 — CVSS 9.8 (critical): A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may…
CVE-2026-8956 — CVSS 9.8 (critical): Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and…
CVE-2026-42217 — CVSS 9.8 (critical): OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture…
CVE-2026-31649 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm()…
CVE-2026-31633 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response() In…
CVE-2026-20889 — CVSS 9.8 (critical): A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted…
CVE-2026-30909 — CVSS 9.8 (critical): Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows. bin2hex, encrypt, aes256gcm_encrypt_afternm and seal…
CVE-2026-2781 — CVSS 9.8 (critical): Integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148…
CVE-2026-2774 — CVSS 9.8 (critical): Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8…
CVE-2026-2762 — CVSS 9.8 (critical): Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird…
CVE-2025-14308 — CVSS 9.8 (critical): An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly…
CVE-2025-27918 — CVSS 9.8 (critical): An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for…
CVE-2025-54957 — CVSS 9.8 (critical): An issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+ bitstream is…
CVE-2025-53518 — CVSS 9.8 (critical): An integer overflow vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch…
CVE-2025-52581 — CVSS 9.8 (critical): An integer overflow vulnerability exists in the GDF parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch…
CVE-2025-30405 — CVSS 9.8 (critical): An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their allocated memory area…
CVE-2025-30404 — CVSS 9.8 (critical): An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially resulting in code…