Vulnerabilities > Integer Overflow or Wraparound

DATE CVE VULNERABILITY TITLE RISK
2017-02-15 CVE-2017-2987 Integer Overflow or Wraparound vulnerability in Adobe Flash Player and Flash Player Desktop Runtime
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable integer overflow vulnerability related to Flash Broker COM.
network
low complexity
adobe CWE-190
8.8
2017-02-13 CVE-2016-8859 Integer Overflow or Wraparound vulnerability in Etalabs Musl 1.1.15
Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.
network
low complexity
etalabs CWE-190
critical
9.8
2017-02-10 CVE-2017-5953 Integer Overflow or Wraparound vulnerability in VIM
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
network
low complexity
vim CWE-190
critical
9.8
2017-02-09 CVE-2016-2147 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
network
low complexity
busybox debian canonical CWE-190
7.5
2017-02-08 CVE-2017-0410 Integer Overflow or Wraparound vulnerability in Google Android
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process.
local
low complexity
google CWE-190
7.8
2017-02-07 CVE-2015-7599 Integer Overflow or Wraparound vulnerability in Windriver Vxworks
Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol is enabled, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a username and password.
network
high complexity
windriver CWE-190
8.1
2017-02-06 CVE-2017-5576 Integer Overflow or Wraparound vulnerability in Linux Kernel
Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted size value in a VC4_SUBMIT_CL ioctl call.
local
low complexity
linux CWE-190
7.8
2017-02-03 CVE-2016-9108 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc.
network
low complexity
fedoraproject artifex CWE-190
7.5
2017-02-03 CVE-2016-9085 Integer Overflow or Wraparound vulnerability in multiple products
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
local
low complexity
webmproject fedoraproject CWE-190
3.3
2017-02-03 CVE-2016-9082 Integer Overflow or Wraparound vulnerability in Cairographics Cairo 1.14.6
Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference) via a large svg file.
local
low complexity
cairographics CWE-190
5.5