Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-190'

View all threats tagged with 'cwe-190'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-190

Threats Tagged 'cwe-190'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-70638: Integer Overflow or Wraparound in ggml-org llama.cppCVE-2026-70638
0

llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocation to wrap and allocate insufficient memory. Attackers can exploit this by providing a crafted n_seq_max value through a malicious model file or JNI call to trigger heap corruption and achieve denial of service or arbitrary code execution on Android applications using the LLaMA-Android binding.

Join the discussion
CVE-2026-43629: Out-of-bounds Write in ggml-org llama.cppCVE-2026-43629
0

llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corrupt heap memory. Attackers can craft malicious state files where cell_count multiplication overflows or exceeds tensor buffer allocation to write attacker-controlled bytes past buffer boundaries, potentially resulting in heap metadata corruption, model weight corruption, or arbitrary code execution via function pointer overwrite.

Join the discussion
CVE-2026-43627: Integer Overflow or Wraparound in ggml-org llama.cppCVE-2026-43627
0

llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap corruption and potentially achieving arbitrary code execution through subsequent batch operations that write past allocated buffer boundaries.

Join the discussion
CVE-2026-19028: CWE-190 Integer overflow or wraparound in The HDF Group HDF5CVE-2026-19028
0

H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5_checksum_fletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by the h5ls or h5dump tools.

Join the discussion
CVE-2026-71261: CWE-190 in mackron dr_libsCVE-2026-71261
0

dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chunk(), a stage-1 capacity estimate truncates the 64-bit W64 chunk sizeInBytes to size_t before dividing by DRWAV_CUE_POINT_BYTES; on 32-bit builds this truncation causes the pre-allocated extra metadata capacity to be computed incorrectly. The subsequent read in drwav__read_cue_to_metadata_obj() computes the actual cue point count and allocation size using the full-precision, attacker-controlled cuePointCount field without cross-checking it against the stage-1 capacity estimate, and the only bounds enforcement on the resulting memory region (drwav__metadata_get_memory()) is a DRWAV_ASSERT, which compiles to a no-op under -DNDEBUG (the default for release builds). A crafted W64 WAV file can therefore cause a heap buffer overflow in any 32-bit application parsing untrusted WAV metadata.

Join the discussion
CVE-2026-21366: CWE-190 Integer Overflow or Wraparound in Qualcomm, Inc. SnapdragonCVE-2026-21366
0

Memory corruption while processing a packet with a size close to the maximum allowed value.

Join the discussion
CVE-2026-65423: CWE-190 in o6 Automation open62541CVE-2026-65423
0

CVE-2026-65423 is a high severity integer overflow vulnerability in the UA_Variant arrayDimensions product computation of the open62541 library by o6 Automation. This flaw may allow a remote attacker with low privileges to trigger an out-of-bounds write, potentially leading to full compromise of confidentiality, integrity, and availability. The affected versions explicitly include 1.3.0, 1.4.0, and 1.5.0. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time.

Join the discussion
CVE-2026-63559: CWE-190 in o6 Automation open62541CVE-2026-63559
0

CVE-2026-63559 is an integer overflow vulnerability in the UA_Variant arrayDimensions computation of the open62541 product by o6 Automation. This flaw may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information. The vulnerability affects versions 1.3.0, 1.4.0, and 1.5.0. It has a high severity with a CVSS score of 7.5. No official patch or remediation guidance is currently available from the vendor.

Join the discussion
CVE-2026-18022: Integer Overflow or Wraparound in pgvectorCVE-2026-18022
0

CVE-2026-18022 is an integer wraparound vulnerability in the IVFFlat index build component of pgvector versions prior to 0.8.6. This flaw allows a database user on 32-bit systems to write data out-of-bounds, potentially leading to arbitrary code execution. The vulnerability has a high severity score of 8.8 and requires low attack complexity with privileges. No official patch or remediation level is currently confirmed.

Join the discussion
CVE-2026-58152: CWE-190 Integer Overflow or Wraparound in Apache Software Foundation Apache Traffic ServerCVE-2026-58152
0

Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3 contain an integer overflow vulnerability in the handling of HPACK/XPACK headers that can lead to memory corruption. This vulnerability is identified as CVE-2026-58152 and is classified under CWE-190. The issue has a medium severity rating with a CVSS score of 5.9 and impacts availability. Fixed versions are 9.2.15 and 10.1.4.

Join the discussion

Showing 1 to 10 of 61 results

Filters:Tag: cwe-190
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses