Vulnerabilities > Integer Overflow or Wraparound

DATE CVE VULNERABILITY TITLE RISK
2017-02-22 CVE-2016-8636 Integer Overflow or Wraparound vulnerability in Linux Kernel
Integer overflow in the mem_check_range function in drivers/infiniband/sw/rxe/rxe_mr.c in the Linux kernel before 4.9.10 allows local users to cause a denial of service (memory corruption), obtain sensitive information from kernel memory, or possibly have unspecified other impact via a write or read request involving the "RDMA protocol over infiniband" (aka Soft RoCE) technology.
local
low complexity
linux CWE-190
7.8
2017-02-17 CVE-2016-7511 Integer Overflow or Wraparound vulnerability in Libdwarf Project Libdwarf 20160613
Integer overflow in the dwarf_die_deliv.c in libdwarf 20160613 allows remote attackers to cause a denial of service (crash) via a crafted file.
local
low complexity
libdwarf-project CWE-190
5.5
2017-02-17 CVE-2016-6872 Integer Overflow or Wraparound vulnerability in Facebook Hhvm
Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
network
low complexity
facebook CWE-190
critical
9.8
2017-02-17 CVE-2016-6871 Integer Overflow or Wraparound vulnerability in Facebook Hhvm
Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a buffer overflow.
network
low complexity
facebook CWE-190
critical
9.8
2017-02-17 CVE-2016-6252 Integer Overflow or Wraparound vulnerability in Shadow Project Shadow 4.2.1
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
local
low complexity
shadow-project CWE-190
7.8
2017-02-15 CVE-2017-0309 Integer Overflow or Wraparound vulnerability in Nvidia GPU Driver
All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where multiple integer overflows may cause improper memory allocation leading to a denial of service or potential escalation of privileges.
local
low complexity
nvidia CWE-190
8.8
2017-02-15 CVE-2016-1889 Integer Overflow or Wraparound vulnerability in Freebsd
Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a crafted device descriptor.
local
low complexity
freebsd CWE-190
7.8
2017-02-15 CVE-2017-2987 Integer Overflow or Wraparound vulnerability in Adobe Flash Player and Flash Player Desktop Runtime
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable integer overflow vulnerability related to Flash Broker COM.
network
low complexity
adobe CWE-190
8.8
2017-02-13 CVE-2016-8859 Integer Overflow or Wraparound vulnerability in Etalabs Musl 1.1.15
Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.
network
low complexity
etalabs CWE-190
critical
9.8
2017-02-10 CVE-2017-5953 Integer Overflow or Wraparound vulnerability in VIM
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
network
low complexity
vim CWE-190
critical
9.8