
CVE-2021-46143 – expat: Integer overflow in doProlog in xmlparse.c
https://notcve.org/view.php?id=CVE-2021-46143
06 Jan 2022 — In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. ... When processing a large number of prefixed XML attributes on a single tag can libexpat can terminate unexpectedly due to integer overflow. ... Issues addressed include code execution, integer overflow, null pointer, out of bounds read, out of bounds write, and server-side request forgery vulnerabilities. • https://github.com/nanopathi/external_expat_AOSP10_r33_CVE-2021-46143 • CWE-190: Integer Overflow or Wraparound •

CVE-2022-20012
https://notcve.org/view.php?id=CVE-2022-20012
04 Jan 2022 — In mdp driver, there is a possible memory corruption due to an integer overflow. • https://corp.mediatek.com/product-security-bulletin/January-2022 • CWE-190: Integer Overflow or Wraparound •

CVE-2021-30275
https://notcve.org/view.php?id=CVE-2021-30275
03 Jan 2022 — Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking Un posible desbordamiento de enteros en la interfaz de alineación de páginas debido a una falta de comprobación de la dirección y el tamaño antes de la alineación en Snapdragon Auto, Snapdragon ... • https://www.qualcomm.com/company/product-security/bulletins/december-2021-bulletin • CWE-190: Integer Overflow or Wraparound •

CVE-2021-30274
https://notcve.org/view.php?id=CVE-2021-30274
03 Jan 2022 — Possible integer overflow in access control initialization interface due to lack and size and address validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking Un posible desbordamiento de enteros en la interfaz de inicialización del control de acceso debido a una falta de comprobación del tamaño y la dirección en Snapdragon Auto, Snapdragon Compute, Sn... • https://www.qualcomm.com/company/product-security/bulletins/december-2021-bulletin • CWE-190: Integer Overflow or Wraparound •

CVE-2021-30267
https://notcve.org/view.php?id=CVE-2021-30267
03 Jan 2022 — Possible integer overflow to buffer overflow due to improper input validation in FTM ARA commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile Un posible desbordamiento de enteros a desbordamiento de búfer debido a una comprobación de entrada inapropiada en los comandos FTM ARA en Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon M... • https://www.qualcomm.com/company/product-security/bulletins/december-2021-bulletin • CWE-190: Integer Overflow or Wraparound •

CVE-2020-11263
https://notcve.org/view.php?id=CVE-2020-11263
03 Jan 2022 — An integer overflow due to improper check performed after the address and size passed are aligned in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking Un desbordamiento de enteros debido a una comprobación inapropiada llevada a cabo después de alinear la dirección y el tamaño pasados en Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, ... • https://www.qualcomm.com/company/product-security/bulletins/december-2021-bulletin • CWE-190: Integer Overflow or Wraparound •

CVE-2021-45960 – expat: Large number of prefixed XML attributes on a single tag can crash libexpat
https://notcve.org/view.php?id=CVE-2021-45960
01 Jan 2022 — Issues addressed include code execution, integer overflow, null pointer, out of bounds read, out of bounds write, and server-side request forgery vulnerabilities. • https://github.com/nanopathi/external_expat_AOSP10_r33_CVE-2021-45960 • CWE-130: Improper Handling of Length Parameter Inconsistency CWE-682: Incorrect Calculation •

CVE-2021-45608
https://notcve.org/view.php?id=CVE-2021-45608
26 Dec 2021 — Certain D-Link, Edimax, NETGEAR, TP-Link, Tenda, and Western Digital devices are affected by an integer overflow by an unauthenticated attacker. • https://kb.netgear.com/000064437/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Multiple-Products-PSV-2021-0278 • CWE-190: Integer Overflow or Wraparound •

CVE-2021-4066 – Gentoo Linux Security Advisory 202208-25
https://notcve.org/view.php?id=CVE-2021-4066
23 Dec 2021 — Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. • https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html • CWE-191: Integer Underflow (Wrap or Wraparound) •

CVE-2021-40417
https://notcve.org/view.php?id=CVE-2021-40417
22 Dec 2021 — Due to an integer overflow with regards to this calculation, this can result in an undersized heap buffer being allocated. • https://talosintelligence.com/vulnerability_reports/TALOS-2021-1426 • CWE-190: Integer Overflow or Wraparound CWE-680: Integer Overflow to Buffer Overflow •