Vulnerabilities > Integer Overflow or Wraparound

DATE CVE VULNERABILITY TITLE RISK
2017-11-29 CVE-2017-8816 Integer Overflow or Wraparound vulnerability in multiple products
The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.
network
low complexity
haxx debian CWE-190
7.5
2017-11-22 CVE-2017-8205 Integer Overflow or Wraparound vulnerability in Huawei Honor 9 Firmware Stanfordal00C00B175
The Bastet driver of Honor 9 Huawei smart phones with software of versions earlier than Stanford-AL10C00B175 has integer overflow vulnerability due to the lack of parameter validation.
network
huawei CWE-190
critical
9.3
2017-11-22 CVE-2017-2717 Integer Overflow or Wraparound vulnerability in Huawei Honor 8 PRO Firmware
honor 8 Pro with software Duke-L09C10B120 and earlier versions,Duke-L09C432B120 and earlier versions,Duke-L09C636B120 and earlier versions has an integer overflow vulnerability.
low complexity
huawei CWE-190
3.3
2017-11-20 CVE-2017-12110 Integer Overflow or Wraparound vulnerability in Libxls Project Libxls 1.4
An exploitable integer overflow vulnerability exists in the xls_appendSST function of libxls 1.4.A specially crafted XLS file can cause memory corruption resulting in remote code execution.
6.8
2017-11-17 CVE-2017-1000229 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.
6.8
2017-11-17 CVE-2017-1000158 Integer Overflow or Wraparound vulnerability in multiple products
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
network
low complexity
python debian CWE-190
critical
9.8
2017-11-16 CVE-2017-0841 Integer Overflow or Wraparound vulnerability in Google Android
A remote code execution vulnerability in the Android system (libutils).
network
google CWE-190
critical
9.3
2017-11-16 CVE-2017-9690 Integer Overflow or Wraparound vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a qbt1000 ioctl handler, an incorrect buffer size check has an integer overflow vulnerability potentially leading to a buffer overflow.
local
low complexity
google CWE-190
7.2
2017-11-16 CVE-2017-13136 Integer Overflow or Wraparound vulnerability in Libbpg Project Libbpg 0.9.7
The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL pointer dereference.
6.8
2017-11-15 CVE-2017-16832 Integer Overflow or Wraparound vulnerability in GNU Binutils 2.29.1
The pe_bfd_read_buildid function in peicode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate size and offset values in the data dictionary, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or possibly have unspecified other impact via a crafted PE file.
local
low complexity
gnu CWE-190
7.8