VulnSea

CWE-190

CVEs classified under CWE-190, newest first.

387 CVEsRSS

CVE-2026-21321High· 7.8
7mo ago

After Effects versions 25.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user

After Effects versions 25.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interactio…

▾ Twilightadobe · after_effectsEPSS 0.22%via NVD
CVE-2026-23876High· 8.1
8mo ago

ImageMagick is free and open-source software used for editing and manipulating digital images

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to w…

▾ Twilightimagemagick · imagemagickEPSS 0.66%via NVD
CVE-2025-14242Medium· 6.5
8mo ago

A flaw was found in vsftpd

A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byt…

▾ SunlitEPSS 0.82%via NVD
CVE-2026-0880High· 8.8
8mo ago

Sandbox escape due to integer overflow in the Graphics component

Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

▾ Twilightmozilla · firefoxEPSS 0.66%via NVD
CVE-2025-65865High· 7.5
9mo ago

An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.

An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ Twilighteprosima · fast_ddsEPSS 0.40%via NVD
CVE-2025-14512Medium· 6.5
9mo ago

A flaw was found in glib

A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote files…

▾ Sunlitgnome · glibEPSS 0.58%via NVD
CVE-2025-14087Medium· 5.6
9mo ago

A flaw was found in GLib (Gnome Lib)

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciou…

▾ Sunlitgnome · glibEPSS 0.83%via NVD
CVE-2025-3500Critical· 9.0PoC
10mo ago

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

▾ Abyssalavast · antivirusEPSS 0.46%via NVD
CVE-2025-34297None
10mo ago

KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platforms where size_t is 32-bit

KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platforms where size_t is 32-bit. The nfft parameter is not validated before being used in a size calculation (sizeof(kiss…

▾ SunlitEPSS 0.17%via NVD
CVE-2025-13601High· 7.7
10mo ago

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would ne…

▾ Twilightredhat · codeready_linux_builderEPSS 0.32%via NVD
CVE-2025-62231High· 7.3
11mo ago

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value …

▾ TwilightEPSS 0.28%via NVD
CVE-2025-7985High· 7.80day
1y ago

Ashlar-Vellum Cobalt VC6 File Parsing Integer Overflow Remote Code Execution Vulnerability

Ashlar-Vellum Cobalt VC6 File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is requi…

▾ Abyssalashlar · cobaltEPSS 0.21%via NVD
CVE-2025-7982High· 7.80day
1y ago

Ashlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution Vulnerability

Ashlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is requir…

▾ Abyssalashlar · cobaltEPSS 0.22%via NVD
CVE-2025-5449Medium· 6.5
1y ago

A flaw was found in the SFTP server message decoding logic of libssh

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads to faile…

▾ Sunlitlibssh · libsshEPSS 0.88%via NVD
CVE-2025-49180High· 7.8
1y ago

A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input

A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input. This issue leads to an integer overflow when computing the total size to allocate.

▾ TwilightEPSS 0.32%via NVD
CVE-2025-49179High· 7.3
1y ago

A flaw was found in the X Record extension

A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.

▾ TwilightEPSS 0.33%via NVD
CVE-2025-49176High· 7.3
1y ago

A flaw was found in the Big Requests extension

A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size check.

▾ TwilightEPSS 0.36%via NVD
CVE-2025-6035Medium· 6.1
1y ago

A flaw was found in GIMP

A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs due to unchecked multiplication of image dimensions, such as width, height, and bytes-per-pixel (img_bpp), which can re…

▾ Sunlitgimp · gimpEPSS 0.57%via NVD
CVE-2025-5916Low· 3.9
1y ago

A vulnerability has been identified in the libarchive library

A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker …

▾ Sunlitlibarchive · libarchiveEPSS 0.18%via NVD
CVE-2025-5914High· 7.8PoC
1y ago

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a…

▾ Midnightlibarchive · libarchiveEPSS 0.44%via NVD
CVE-2025-47712Medium· 6.5
1y ago

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal erro…

▾ Sunlitnbdkit_project · nbdkitEPSS 0.48%via NVD
CVE-2025-4945Low· 3.7
1y ago

A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software

A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger…

▾ SunlitEPSS 0.67%via NVD
CVE-2025-22055Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: net: fix geneve_opt length integer overflow struct geneve_opt uses 5 bit length for each single option, which means every vary size option should be smaller than 128 b…

In the Linux kernel, the following vulnerability has been resolved: net: fix geneve_opt length integer overflow struct geneve_opt uses 5 bit length for each single option, which means every vary size option should be smaller than 128 b…

▾ Sunlitlinux · linux_kernelEPSS 0.25%via NVD
CVE-2025-3360Low· 3.7
1y ago

A flaw was found in GLib

A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function.

▾ SunlitEPSS 0.47%via NVD
CVE-2024-40635Medium· 4.6PoC
1y ago

containerd: containerd has an integer overflow in User ID handling (CVE-2024-40635)

A flaw was found in containerd package. Containers launched with a User set as a UID:GID larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This issue could ca…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.29%via CSAF
CVE-2024-45778Medium· 4.1
1y ago

A stack overflow flaw was found when reading a BFS file system

A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to an uncontrolled loop, causing grub2 to crash.

▾ Sunlitgnu · grub2EPSS 0.29%via NVD
CVE-2024-45779Medium· 6.0
1y ago

An integer overflow flaw was found in the BFS file system driver in grub2

An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails to validate the number of extent entries to be read. A crafted or corrupted BFS filesystem may cause …

▾ Sunlitgnu · grub2EPSS 0.29%via NVD
CVE-2025-0678High· 7.8
1y ago

A flaw was found in grub2

A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for intege…

▾ Twilightgnu · grub2EPSS 0.28%via NVD
CVE-2025-21748Critical· 9.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix integer overflows on 32 bit systems On 32bit systems the addition operations in ipc_msg_alloc() can potentially overflow leading to memory corruption. Add b…

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix integer overflows on 32 bit systems On 32bit systems the addition operations in ipc_msg_alloc() can potentially overflow leading to memory corruption. Add b…

▾ Midnightlinux · linux_kernelEPSS 0.61%via NVD
CVE-2024-57973Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl->tot_len" variable is controlled by the user

In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl->tot_len" variable is controlled by the user. It comes from process_responses(). On 32bit systems, th…

▾ Sunlitlinux · linux_kernelEPSS 0.67%via NVD
CWE-190 vulnerabilities (CVEs) — page 12 · VulnSea