Vulnerabilities > Integer Overflow or Wraparound

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-33018 Integer Overflow or Wraparound vulnerability in Qualcomm products
Memory corruption while using the UIM diag command to get the operators name.
local
low complexity
qualcomm CWE-190
7.8
2023-12-05 CVE-2023-33022 Integer Overflow or Wraparound vulnerability in Qualcomm products
Memory corruption in HLOS while invoking IOCTL calls from user-space.
local
low complexity
qualcomm CWE-190
7.8
2023-12-05 CVE-2023-33107 Integer Overflow or Wraparound vulnerability in Qualcomm products
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
local
low complexity
qualcomm CWE-190
7.8
2023-12-05 CVE-2023-42562 Integer Overflow or Wraparound vulnerability in Samsung Android 12.0/13.0/14.0
Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
local
low complexity
samsung CWE-190
7.8
2023-12-05 CVE-2023-42563 Integer Overflow or Wraparound vulnerability in Samsung Android 12.0/13.0/14.0
Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
local
low complexity
samsung CWE-190
7.8
2023-11-29 CVE-2023-6345 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file.
network
low complexity
google debian fedoraproject microsoft CWE-190
critical
9.6
2023-11-28 CVE-2023-4398 Integer Overflow or Wraparound vulnerability in Zyxel ZLD
An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions on an affected device by sending a crafted IKE packet.
network
low complexity
zyxel CWE-190
7.5
2023-11-21 CVE-2021-27502 Integer Overflow or Wraparound vulnerability in TI products
Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution.
local
low complexity
ti CWE-190
7.8
2023-11-21 CVE-2021-27504 Integer Overflow or Wraparound vulnerability in multiple products
Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code execution.
local
low complexity
amazon ti CWE-190
7.8
2023-11-20 CVE-2021-22636 Integer Overflow or Wraparound vulnerability in TI products
Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution.
local
low complexity
ti CWE-190
7.8