Skip to main content

CWE archive

CWE-190 CVEs

Programmatic archive

3,302 CVEs tagged with CWE-190432 Critical, 1,919 High, 852 Medium, 97 Low, 2 Unrated.

CVE-2016-4490

Published Feb 24, 2017

Integer overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to inconsistent us…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4489

Published Feb 24, 2017

Integer overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2226

Published Feb 24, 2017

Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer ove…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6308

Published Feb 24, 2017

An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8636

Published Feb 22, 2017

Integer overflow in the mem_check_range function in drivers/infiniband/sw/rxe/rxe_mr.c in the Linux kernel before 4.9.10 allows local users to cause a denial of service (memory co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7511

Published Feb 17, 2017

Integer overflow in the dwarf_die_deliv.c in libdwarf 20160613 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6872

Published Feb 17, 2017

Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6871

Published Feb 17, 2017

Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a buffer overflow.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6252

Published Feb 17, 2017

Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1889

Published Feb 15, 2017

Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a craf…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8859

Published Feb 13, 2017

Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bound…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-5953

Published Feb 10, 2017

vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a r…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-0410

Published Feb 8, 2017

An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7599

Published Feb 7, 2017

Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol is enabled, allows remote att…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5576

Published Feb 6, 2017

Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 allows local users to cause a denial of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9108

Published Feb 3, 2017

Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9082

Published Feb 3, 2017

Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference) via a large svg file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4352

Published Feb 3, 2017

Integer overflow in the demuxer function in libmpdemux/demux_gif.c in Mplayer allows remote attackers to cause a denial of service (crash) via large dimensions in a gif file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10164

Published Feb 1, 2017

Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-o…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 3,051-3,075 of 3,302 CVEsPage 123 of 133