Vulnerabilities > Integer Overflow or Wraparound

DATE CVE VULNERABILITY TITLE RISK
2017-02-09 CVE-2016-2147 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
network
low complexity
busybox debian canonical CWE-190
7.5
2017-02-08 CVE-2017-0410 Integer Overflow or Wraparound vulnerability in Google Android
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process.
local
low complexity
google CWE-190
7.8
2017-02-07 CVE-2015-7599 Integer Overflow or Wraparound vulnerability in Windriver Vxworks
Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol is enabled, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a username and password.
network
high complexity
windriver CWE-190
8.1
2017-02-06 CVE-2017-5576 Integer Overflow or Wraparound vulnerability in Linux Kernel
Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted size value in a VC4_SUBMIT_CL ioctl call.
local
low complexity
linux CWE-190
7.8
2017-02-03 CVE-2016-9108 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc.
network
low complexity
fedoraproject artifex CWE-190
7.5
2017-02-03 CVE-2016-9085 Integer Overflow or Wraparound vulnerability in multiple products
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
local
low complexity
webmproject fedoraproject CWE-190
3.3
2017-02-03 CVE-2016-9082 Integer Overflow or Wraparound vulnerability in Cairographics Cairo 1.14.6
Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference) via a large svg file.
local
low complexity
cairographics CWE-190
5.5
2017-02-03 CVE-2016-4352 Integer Overflow or Wraparound vulnerability in Libavformat Project Libavformat 57.34.103
Integer overflow in the demuxer function in libmpdemux/demux_gif.c in Mplayer allows remote attackers to cause a denial of service (crash) via large dimensions in a gif file.
local
low complexity
libavformat-project CWE-190
5.5
2017-02-01 CVE-2016-10164 Integer Overflow or Wraparound vulnerability in X.Org Libxpm
Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.
network
low complexity
x-org CWE-190
critical
9.8
2017-01-30 CVE-2016-9132 Integer Overflow or Wraparound vulnerability in Botan Project Botan
In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed.
network
low complexity
botan-project CWE-190
critical
9.8