817 vulnerabilities classified as CWE-190 (整数溢出或超界折返). AI Chinese analysis included.
CWE-190 represents a critical logic flaw where arithmetic operations exceed the maximum capacity of the assigned integer data type, causing the value to wrap around to a negative number or zero. Attackers typically exploit this vulnerability by manipulating input values to trigger the overflow, thereby bypassing security checks that assume the resulting number remains positive or within expected bounds. This often leads to severe consequences such as buffer overflows, memory corruption, or unauthorized access. To prevent such issues, developers must implement rigorous input validation and use safe arithmetic libraries that detect potential overflows before execution. Additionally, employing static analysis tools and adhering to secure coding standards ensures that integer calculations are handled with appropriate bounds checking, effectively mitigating the risk of wraparound errors in production environments.
img_t table_ptr; /*struct containing img data, 10kB each*/ int num_imgs; ... num_imgs = get_num_imgs(); table_ptr = (img_t*)malloc(sizeof(img_t)*num_imgs); ...nresp = packet_get_int(); if (nresp > 0) { response = xmalloc(nresp*sizeof(char*)); for (i = 0; i < nresp; i++) response[i] = packet_get_string(NULL); }| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2022-44425 | UNISOC chipset 输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2023-01-04 |
| CVE-2022-44426 | Google Android 输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2023-01-04 |
| CVE-2022-44432 | Google Android OS和unisoc部分产品输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2023-01-04 |
| CVE-2022-34673 | NVIDIA GPU Display Driver 缓冲区错误漏洞 — NVIDIA GPU Display Driver for Linux | 4.4 | Medium | 2022-12-30 |
| CVE-2022-42256 | NVIDIA GPU Display Driver 输入验证错误漏洞 — vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) | 5.3 | Medium | 2022-12-30 |
| CVE-2022-42257 | NVIDIA GPU Display Driver 输入验证错误漏洞 — vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) | 5.3 | Medium | 2022-12-30 |
| CVE-2022-42258 | NVIDIA GPU Display Driver 输入验证错误漏洞 — vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) | 5.3 | Medium | 2022-12-30 |
| CVE-2022-42259 | NVIDIA GPU Display Driver 输入验证错误漏洞 — vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) | 4.4 | Medium | 2022-12-30 |
| CVE-2022-42263 | NVIDIA GPU Display Driver 输入验证错误漏洞 — vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) | 7.1 | High | 2022-12-30 |
| CVE-2022-42265 | NVIDIA GPU Display Driver 输入验证错误漏洞 — NVIDIA GPU Display Driver for Linux | 5.3 | Medium | 2022-12-30 |
| CVE-2022-4398 | Integer Overflow or Wraparound in radareorg/radare2 — radareorg/radare2 | 5.5 | - | 2022-12-10 |
| CVE-2022-23484 | Integer Overflow in xrdp — xrdp | 8.2 | High | 2022-12-09 |
| CVE-2022-39907 | SAMSUNG Mobile devices 输入验证错误漏洞 — Samsung Mobile Devices | 6.9 | Medium | 2022-12-08 |
| CVE-2022-42763 | UNISOC chipset 输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8008 | 5.5 | - | 2022-12-06 |
| CVE-2022-42764 | UNISOC chipset 输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8009 | 5.5 | - | 2022-12-06 |
| CVE-2022-42765 | UNISOC chipset 输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8010 | 5.5 | - | 2022-12-06 |
| CVE-2022-42767 | UNISOC chipset 输入验证错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8012 | 5.5 | - | 2022-12-06 |
| CVE-2022-32775 | Abode Iota 输入验证错误漏洞 — iota All-In-One Security Kit | 8.8 | - | 2022-10-25 |
| CVE-2022-39105 | UNISOC chipset 缓冲区错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2022-10-14 |
| CVE-2021-3782 | Canonical Ubuntu Linux 输入验证错误漏洞 — wayland | 9.8 | - | 2022-09-23 |
| CVE-2022-35951 | Redis subject to Integer Overflow leading to Remote Code Execution via Heap Overflow — redis | 7.0 | High | 2022-09-23 |
| CVE-2022-36015 | Integer overflow in math ops in TensorFlow — tensorflow | 5.9 | Medium | 2022-09-16 |
| CVE-2022-35940 | Int overflow in `RaggedRangeOp` in Tensoflow — tensorflow | 5.9 | Medium | 2022-09-16 |
| CVE-2021-20224 | ImageMagick 输入验证错误漏洞 — ImageMagick | 5.5 | - | 2022-08-25 |
| CVE-2021-20304 | ILM OpenEXR 输入验证错误漏洞 — OpenEXR | 6.5 | - | 2022-08-23 |
| CVE-2022-36008 | Message length overflow in frontier — frontier | 7.1 | High | 2022-08-19 |
| CVE-2022-2831 | Blender 缓冲区错误漏洞 — Blender | 7.5 | - | 2022-08-16 |
| CVE-2022-38216 | Mapbox 输入验证错误漏洞 — Mapbox | 7.5 | - | 2022-08-16 |
| CVE-2022-1921 | GStreamer 输入验证错误漏洞 — GStreamer | 7.8 | - | 2022-07-19 |
| CVE-2022-2454 | Integer Overflow or Wraparound in gpac/gpac — gpac/gpac | 7.8 | - | 2022-07-19 |
Vulnerabilities classified as CWE-190 (整数溢出或超界折返) represent 817 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.