CWE-190
CVEs classified under CWE-190, newest first.
387 CVEsRSS
CVE-2026-61937High· 7.8Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-59127High· 7.8Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-62886High· 7.8Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-62897High· 7.0.NET Framework Remote Code Execution Vulnerability
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-19389High· 7.1Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled l…
CVE-2026-15534Medium· 5.7Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each…
Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each…
CVE-2026-70638High· 7.8PoCllama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflo…
llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflo…
CVE-2026-43629High· 8.1llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access…
llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access…
CVE-2026-43627High· 7.8llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes
llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pa…
CVE-2026-45103High· 7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header using unsigned int arithmetic with no overflow check. When an…
CVE-2026-53466Medium· 6.5ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
CVE-2026-17673Critical· 9.6Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page
Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-64422High· 7.1In the Linux kernel, the following vulnerability has been resolved: net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes Reject invalid `net.ipv4.tcp_reordering` values before they reach TCP socket state
In the Linux kernel, the following vulnerability has been resolved: net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes Reject invalid `net.ipv4.tcp_reordering` values before they reach TCP socket state. The sysctl is sto…
GHSA-26gq-p25f-99cpHighfrp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
CVE-2026-62343Medium· 4.7ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided
ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided
CVE-2026-62946Medium· 5.1ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
CVE-2026-53910Nonediff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations
diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for …
CVE-2026-16517Low· 2.9A signed integer overflow vulnerability was found in libarchive's ZIP writer
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the a…
CVE-2026-59117High· 7.5Windows Terminal Remote Code Execution Vulnerability
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
CVE-2026-54109High· 7.8Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVE-2026-55012High· 7.8Microsoft Defender Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
CVE-2026-50299Medium· 6.8Windows Storage Spaces Direct Remote Code Execution Vulnerability
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-50298Medium· 6.8Windows Spaceport.sys Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-50306High· 7.8Windows TCP/IP Elevation of Privilege Vulnerability
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-50347High· 7.8Windows Data.dll Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
CVE-2026-50310Medium· 4.7Windows Human Interface Device Information Disclosure Vulnerability
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.
CVE-2026-50435High· 7.8Windows Overlay Filter Elevation of Privilege Vulnerability
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
CVE-2026-54115High· 7.8Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
CVE-2026-55048High· 7.8Microsoft Excel Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55026Medium· 6.2Microsoft Office Information Disclosure Vulnerability
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.