Vulnerabilities > Integer Overflow or Wraparound

DATE CVE VULNERABILITY TITLE RISK
2017-04-09 CVE-2017-7603 Integer Overflow or Wraparound vulnerability in Libaacplus Project Libaacplus 2.0.2
au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file.
local
low complexity
libaacplus-project CWE-190
7.8
2017-04-09 CVE-2017-7602 Integer Overflow or Wraparound vulnerability in Libtiff 4.0.7
LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
local
low complexity
libtiff CWE-190
7.8
2017-04-07 CVE-2017-0576 Integer Overflow or Wraparound vulnerability in Linux Kernel 3.10/3.18
An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
local
high complexity
linux CWE-190
7.0
2017-04-07 CVE-2017-0553 Integer Overflow or Wraparound vulnerability in Google Android
An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi service.
local
high complexity
google CWE-190
7.0
2017-04-06 CVE-2016-10319 Integer Overflow or Wraparound vulnerability in ARM Trusted Firmware Project ARM Trusted Firmware 1.2/1.3
In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows.
network
high complexity
arm-trusted-firmware-project CWE-190
5.9
2017-04-02 CVE-2016-8795 Integer Overflow or Wraparound vulnerability in Huawei products
Huawei CloudEngine 12800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 5800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 6800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 7800 with software V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 8800 with software V100R006C00; and Secospace USG6600 with software V500R001C00 allow remote unauthenticated attackers to craft specific IPFPM packets to trigger an integer overflow and cause the device to reset.
network
high complexity
huawei CWE-190
5.9
2017-04-02 CVE-2016-6177 Integer Overflow or Wraparound vulnerability in Huawei Oceanstor 5800 V3 Firmware V300R003C00
The Huawei OceanStor 5800 V300R003C00 has an integer overflow vulnerability.
network
low complexity
huawei CWE-190
6.5
2017-04-02 CVE-2017-2440 Integer Overflow or Wraparound vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-190
7.8
2017-04-01 CVE-2017-7395 Integer Overflow or Wraparound vulnerability in Tigervnc 1.7.1
In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.
network
low complexity
tigervnc CWE-190
6.5
2017-03-29 CVE-2017-7294 Integer Overflow or Wraparound vulnerability in Linux Kernel
The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.6 does not validate addition of certain levels data, which allows local users to trigger an integer overflow and out-of-bounds write, and cause a denial of service (system hang or crash) or possibly gain privileges, via a crafted ioctl call for a /dev/dri/renderD* device.
local
low complexity
linux CWE-190
7.8