Vulnerabilities > Integer Overflow or Wraparound

DATE CVE VULNERABILITY TITLE RISK
2022-05-03 CVE-2021-27419 Integer Overflow or Wraparound vulnerability in Uclibc-Ng Project Uclibc-Ng
uClibc-ng versions prior to 1.0.37 are vulnerable to integer wrap-around in functions malloc-simple.
network
low complexity
uclibc-ng-project CWE-190
critical
9.8
2022-05-03 CVE-2021-27421 Integer Overflow or Wraparound vulnerability in NXP Mcuxpresso Software Development KIT
NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.
network
low complexity
nxp CWE-190
critical
9.8
2022-05-03 CVE-2021-27425 Integer Overflow or Wraparound vulnerability in Cesanta Mongoose OS 2.17.0
Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc.
network
low complexity
cesanta CWE-190
critical
9.8
2022-05-03 CVE-2021-27427 Integer Overflow or Wraparound vulnerability in Riot-Os Riot 2020.01.1
RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
network
low complexity
riot-os CWE-190
critical
9.8
2022-05-03 CVE-2021-27431 Integer Overflow or Wraparound vulnerability in ARM Cmsis-Rtos
ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalent) function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or injected code execution.
network
low complexity
arm CWE-190
critical
9.8
2022-05-03 CVE-2021-27433 Integer Overflow or Wraparound vulnerability in ARM Mbed Ualloc 1.3.0
ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
network
low complexity
arm CWE-190
critical
9.8
2022-05-03 CVE-2021-27435 Integer Overflow or Wraparound vulnerability in ARM Mbed 6.3.0
ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
network
low complexity
arm CWE-190
critical
9.8
2022-05-03 CVE-2021-27439 Integer Overflow or Wraparound vulnerability in Tencent Tencentos-Tiny 3.1.0
TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of effective memory allocation size.
network
low complexity
tencent CWE-190
critical
9.8
2022-05-03 CVE-2022-20107 Integer Overflow or Wraparound vulnerability in multiple products
In subtitle service, there is a possible application crash due to an integer overflow.
local
low complexity
google linux CWE-190
4.4
2022-05-03 CVE-2022-21743 Integer Overflow or Wraparound vulnerability in Google Android
In ion, there is a possible use after free due to an integer overflow.
local
low complexity
google CWE-190
7.8