861 vulnerabilities classified as CWE-190 (整数溢出或超界折返). AI Chinese analysis included.
CWE-190 represents a critical logic flaw where arithmetic operations exceed the maximum capacity of the assigned integer data type, causing the value to wrap around to a negative number or zero. Attackers typically exploit this vulnerability by manipulating input values to trigger the overflow, thereby bypassing security checks that assume the resulting number remains positive or within expected bounds. This often leads to severe consequences such as buffer overflows, memory corruption, or unauthorized access. To prevent such issues, developers must implement rigorous input validation and use safe arithmetic libraries that detect potential overflows before execution. Additionally, employing static analysis tools and adhering to secure coding standards ensures that integer calculations are handled with appropriate bounds checking, effectively mitigating the risk of wraparound errors in production environments.
img_t table_ptr; /*struct containing img data, 10kB each*/ int num_imgs; ... num_imgs = get_num_imgs(); table_ptr = (img_t*)malloc(sizeof(img_t)*num_imgs); ...nresp = packet_get_int(); if (nresp > 0) { response = xmalloc(nresp*sizeof(char*)); for (i = 0; i < nresp; i++) response[i] = packet_get_string(NULL); }| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2022-24963 | Apache Portable Runtime (APR): out-of-bound writes in the apr_encode family of functions — Apache Portable Runtime (APR) | 9.8 | - | 2023-01-31 |
| CVE-2022-35977 | Integer overflow in certain command arguments can drive Redis to OOM panic — redis | 5.5 | Medium | 2023-01-20 |
| CVE-2023-22458 | Integer overflow in multiple Redis commands can lead to denial-of-service — redis | 5.5 | Medium | 2023-01-20 |
| CVE-2023-21579 | Adobe Acrobat Reader DC Font Parsing Integer Overflow Remote Code Execution Vulnerability — Acrobat Reader | 7.8 | High | 2023-01-18 |
| CVE-2022-23521 | gitattributes parsing integer overflow in git — git | 9.8 | Critical | 2023-01-17 |
| CVE-2022-41903 | Integer overflow in `git archive`, `git log --format` leading to RCE in git — git | 9.8 | Critical | 2023-01-17 |
| CVE-2022-1812 | Integer Overflow or Wraparound in publify/publify — publify/publify | 9.1 | - | 2023-01-14 |
| CVE-2022-40983 | Qt 输入验证错误漏洞 — Qt | 8.8 | - | 2023-01-12 |
| CVE-2022-3515 | libksba 输入验证错误漏洞 — libksba | 9.8 | - | 2023-01-12 |
| CVE-2023-21765 | Windows Print Spooler Elevation of Privilege Vulnerability — Windows 10 Version 1809 | 7.8 | High | 2023-01-10 |
| CVE-2023-21754 | Windows Kernel Elevation of Privilege Vulnerability — Windows 10 Version 1809 | 7.8 | High | 2023-01-10 |
| CVE-2023-21730 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability — Windows 10 Version 1809 | 7.8 | High | 2023-01-10 |
| CVE-2023-21561 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability — Windows 10 Version 1809 | 7.8 | High | 2023-01-10 |
| CVE-2023-21557 | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability — Windows 10 Version 1809 | 7.5 | High | 2023-01-10 |
| CVE-2022-44425 | UNISOC chipset 输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2023-01-04 |
| CVE-2022-44426 | Google Android 输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2023-01-04 |
| CVE-2022-44432 | Google Android OS和unisoc部分产品输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2023-01-04 |
| CVE-2022-34673 | NVIDIA GPU Display Driver 缓冲区错误漏洞 — NVIDIA GPU Display Driver for Linux | 4.4 | Medium | 2022-12-30 |
| CVE-2022-42256 | NVIDIA GPU Display Driver 输入验证错误漏洞 — vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) | 5.3 | Medium | 2022-12-30 |
| CVE-2022-42257 | NVIDIA GPU Display Driver 输入验证错误漏洞 — vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) | 5.3 | Medium | 2022-12-30 |
| CVE-2022-42258 | NVIDIA GPU Display Driver 输入验证错误漏洞 — vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) | 5.3 | Medium | 2022-12-30 |
| CVE-2022-42259 | NVIDIA GPU Display Driver 输入验证错误漏洞 — vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) | 4.4 | Medium | 2022-12-30 |
| CVE-2022-42263 | NVIDIA GPU Display Driver 输入验证错误漏洞 — vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) | 7.1 | High | 2022-12-30 |
| CVE-2022-42265 | NVIDIA GPU Display Driver 输入验证错误漏洞 — NVIDIA GPU Display Driver for Linux | 5.3 | Medium | 2022-12-30 |
| CVE-2022-4398 | Integer Overflow or Wraparound in radareorg/radare2 — radareorg/radare2 | 5.5 | - | 2022-12-10 |
| CVE-2022-23484 | Integer Overflow in xrdp — xrdp | 8.2 | High | 2022-12-09 |
| CVE-2022-39907 | SAMSUNG Mobile devices 输入验证错误漏洞 — Samsung Mobile Devices | 6.9 | Medium | 2022-12-08 |
| CVE-2022-42763 | UNISOC chipset 输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8008 | 5.5 | - | 2022-12-06 |
| CVE-2022-42764 | UNISOC chipset 输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8009 | 5.5 | - | 2022-12-06 |
| CVE-2022-42765 | UNISOC chipset 输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8010 | 5.5 | - | 2022-12-06 |
Vulnerabilities classified as CWE-190 (整数溢出或超界折返) represent 861 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.