1195 vulnerabilities classified as CWE-190 (整数溢出或超界折返). AI Chinese analysis included.
CWE-190 represents a critical logic flaw where arithmetic operations exceed the maximum capacity of the assigned integer data type, causing the value to wrap around to a negative number or zero. Attackers typically exploit this vulnerability by manipulating input values to trigger the overflow, thereby bypassing security checks that assume the resulting number remains positive or within expected bounds. This often leads to severe consequences such as buffer overflows, memory corruption, or unauthorized access. To prevent such issues, developers must implement rigorous input validation and use safe arithmetic libraries that detect potential overflows before execution. Additionally, employing static analysis tools and adhering to secure coding standards ensures that integer calculations are handled with appropriate bounds checking, effectively mitigating the risk of wraparound errors in production environments.
img_t table_ptr; /*struct containing img data, 10kB each*/ int num_imgs; ... num_imgs = get_num_imgs(); table_ptr = (img_t*)malloc(sizeof(img_t)*num_imgs); ...
nresp = packet_get_int(); if (nresp > 0) { response = xmalloc(nresp*sizeof(char*)); for (i = 0; i < nresp; i++) response[i] = packet_get_string(NULL); }
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2019-3856 | libssh2 输入验证错误漏洞 — libssh2 | 8.8 | - | 2019-03-25 |
| CVE-2019-3857 | libssh2 输入验证错误漏洞 — libssh2 | 8.8 | - | 2019-03-25 |
| CVE-2019-3863 | libssh2 缓冲区错误漏洞 — libssh2 | 8.8 | - | 2019-03-25 |
| CVE-2019-3855 | libssh2 输入验证错误漏洞 — libssh2 | 8.8 | - | 2019-03-21 |
| CVE-2018-16881 | Adiscon Rsyslog imptcp模块输入验证错误漏洞 — rsyslog: | 7.5 | - | 2019-01-25 |
| CVE-2018-11458 | 多款Siemens产品数字错误漏洞 — SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.7, SINUMERIK 840D sl V4.8 | 8.1 | - | 2018-12-12 |
| CVE-2016-2120 | PowerDNS Authoritative Server 输入验证错误漏洞 — pdns | 6.5 | - | 2018-11-01 |
| CVE-2016-6328 | libexif 数字错误漏洞 — libexif | 8.1 | - | 2018-10-31 |
| CVE-2018-16839 | Haxx curl 缓冲区错误漏洞 — curl: | 7.5 | - | 2018-10-31 |
| CVE-2018-14634 | Linux kernel 输入验证错误漏洞 — kernel | 7.8 | - | 2018-09-25 |
| CVE-2016-9583 | JasPer 缓冲区错误漏洞 — jasper | 7.8 | - | 2018-08-01 |
| CVE-2016-9580 | OpenJPEG 数字错误漏洞 — openjpeg2 | 8.8 | - | 2018-08-01 |
| CVE-2016-8622 | Haxx libcurl 缓冲区错误漏洞 — curl | 9.8 | - | 2018-07-31 |
| CVE-2017-7482 | Linux kernel 缓冲区错误漏洞 — kernel: | 8.8 | - | 2018-07-30 |
| CVE-2018-1124 | procps-ng 数字错误漏洞 — procps-ng | 7.8 | - | 2018-05-23 |
| CVE-2018-1126 | procps-ng 安全漏洞 — procps-ng, procps | 9.8 | - | 2018-05-23 |
| CVE-2016-9601 | Artifex Software Ghostscript 数字错误漏洞 — ghostscript | 5.5 | - | 2018-04-23 |
| CVE-2018-1084 | Corosync 数字错误漏洞 — corosync | 7.5 | - | 2018-04-12 |
| CVE-2017-17408 | Bitdefender Internet Security 安全漏洞 — Bitdefender Internet Security | 8.8 | - | 2017-12-21 |
| CVE-2017-17409 | Bitdefender Internet Security 安全漏洞 — Bitdefender Internet Security | 8.8 | - | 2017-12-21 |
| CVE-2017-10954 | Bitdefender Internet Security 安全漏洞 — Bitdefender Internet Security | 8.8 | - | 2017-10-31 |
| CVE-2017-9282 | Micro Focus VisiBroker 数字错误漏洞 — Micro Focus VisiBroker | 9.8 | - | 2017-09-21 |
| CVE-2017-7542 | Linux kernel 输入验证错误漏洞 — Linux kernel versions up to and including 4.12 | 5.5 | - | 2017-07-21 |
| CVE-2017-7529 | F5 Nginx 输入验证错误漏洞 — nginx | 7.5 | - | 2017-07-13 |
| CVE-2014-9192 | Trihedral Engineering Limited VTScada Integer Overflow — VTS | 7.5 | - | 2014-12-11 |
Vulnerabilities classified as CWE-190 (整数溢出或超界折返) represent 1195 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.