Vulnerabilities > Integer Overflow or Wraparound

DATE CVE VULNERABILITY TITLE RISK
2021-07-22 CVE-2021-35942 Integer Overflow or Wraparound vulnerability in multiple products
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information.
network
low complexity
gnu netapp debian CWE-190
critical
9.1
2021-07-21 CVE-2020-19490 Integer Overflow or Wraparound vulnerability in Tinyexr Project Tinyexr 0.9.5
tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
local
low complexity
tinyexr-project CWE-190
5.5
2021-07-21 CVE-2020-19497 Integer Overflow or Wraparound vulnerability in Matio Project Matio 1.5.17
Integer overflow vulnerability in Mat_VarReadNextInfo5 in mat5.c in tbeu matio (aka MAT File I/O Library) 1.5.17, allows attackers to cause a Denial of Service or possibly other unspecified impacts.
network
low complexity
matio-project CWE-190
8.8
2021-07-20 CVE-2021-33909 Integer Overflow or Wraparound vulnerability in multiple products
fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.
7.8
2021-07-19 CVE-2021-20110 Integer Overflow or Wraparound vulnerability in Zohocorp Manageengine Assetexplorer 1.0.34
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address.
network
low complexity
zohocorp CWE-190
critical
9.8
2021-07-13 CVE-2020-22874 Integer Overflow or Wraparound vulnerability in Jsish
Integer overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute arbitrary code.
network
low complexity
jsish CWE-190
critical
9.8
2021-07-13 CVE-2020-22875 Integer Overflow or Wraparound vulnerability in Jsish
Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code.
network
low complexity
jsish CWE-190
critical
9.8
2021-07-12 CVE-2020-7872 Integer Overflow or Wraparound vulnerability in Hmtalk Daviewindy 8.98.4/8.98.7
DaviewIndy v8.98.7.0 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed format file that is mishandled by DaviewIndy.
local
low complexity
hmtalk CWE-190
7.8
2021-07-07 CVE-2021-21807 Integer Overflow or Wraparound vulnerability in Accusoft Imagegear 19.9
An integer overflow vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.9.
network
low complexity
accusoft CWE-190
critical
9.8
2021-07-07 CVE-2021-32714 Integer Overflow or Wraparound vulnerability in Hyper
hyper is an HTTP library for Rust.
network
low complexity
hyper CWE-190
critical
9.1