Vulnerabilities > Integer Overflow or Wraparound

DATE CVE VULNERABILITY TITLE RISK
2017-11-17 CVE-2017-1000229 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.
local
low complexity
optipng-project debian CWE-190
7.8
2017-11-17 CVE-2017-1000158 Integer Overflow or Wraparound vulnerability in multiple products
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
network
low complexity
python debian CWE-190
critical
9.8
2017-11-16 CVE-2017-0841 Integer Overflow or Wraparound vulnerability in Google Android
A remote code execution vulnerability in the Android system (libutils).
local
low complexity
google CWE-190
7.8
2017-11-16 CVE-2017-9690 Integer Overflow or Wraparound vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a qbt1000 ioctl handler, an incorrect buffer size check has an integer overflow vulnerability potentially leading to a buffer overflow.
local
low complexity
google CWE-190
7.8
2017-11-16 CVE-2017-11085 Integer Overflow or Wraparound vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an integer overflow leading to a buffer overflow due to improper bound checking in msm_audio_effects_virtualizer_handler, file msm-audio-effects-q6-v2.c
local
low complexity
google CWE-190
7.8
2017-11-16 CVE-2017-13136 Integer Overflow or Wraparound vulnerability in Libbpg Project Libbpg 0.9.7
The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL pointer dereference.
network
low complexity
libbpg-project CWE-190
8.8
2017-11-15 CVE-2017-16832 Integer Overflow or Wraparound vulnerability in GNU Binutils 2.29.1
The pe_bfd_read_buildid function in peicode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate size and offset values in the data dictionary, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or possibly have unspecified other impact via a crafted PE file.
local
low complexity
gnu CWE-190
7.8
2017-11-15 CVE-2017-16831 Integer Overflow or Wraparound vulnerability in GNU Binutils 2.29.1
coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate the symbol count, which allows remote attackers to cause a denial of service (integer overflow and application crash, or excessive memory allocation) or possibly have unspecified other impact via a crafted PE file.
local
low complexity
gnu CWE-190
7.8
2017-11-15 CVE-2017-16830 Integer Overflow or Wraparound vulnerability in GNU Binutils 2.29.1
The print_gnu_property_note function in readelf.c in GNU Binutils 2.29.1 does not have integer-overflow protection on 32-bit platforms, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or possibly have unspecified other impact via a crafted ELF file.
local
low complexity
gnu CWE-190
7.8
2017-11-15 CVE-2017-16828 Integer Overflow or Wraparound vulnerability in GNU Binutils 2.29.1
The display_debug_frames function in dwarf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (integer overflow and heap-based buffer over-read, and application crash) or possibly have unspecified other impact via a crafted ELF file, related to print_debug_frame.
local
low complexity
gnu CWE-190
7.8