CWE-191— Integer Underflow
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.— MITRE CWE catalog
608 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-191page 1 of 13
- CVE-2014-0497CRITICALCVSS 9.8EG 9.8⚠ KEV2014-02-05
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
- CVE-2022-0185CRITICALCVSS 8.4EG 9.0⚠ KEV2022-02-11
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user names…
- CVE-2021-31956CRITICALCVSS 7.8EG 9.0⚠ KEV2021-06-08
Windows NTFS Elevation of Privilege Vulnerability
- CVE-2007-0063HIGHCVSS v2 10.0EG 10.02007-09-21
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before …
- CVE-2026-59090CRITICALCVSS 9.9EG 9.92026-08-10
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enab…
- CVE-2026-84411CRITICALCVSS 9.8EG 9.82026-10-02
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbit…
- CVE-2026-91103CRITICALCVSS 9.8EG 9.82026-09-16
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, infor…
- CVE-2026-69824CRITICALCVSS 9.8EG 9.82026-09-08
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
- CVE-2026-69276CRITICALCVSS 9.8EG 9.82026-09-08
Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.
- CVE-2026-49181CRITICALCVSS 9.8EG 9.82026-07-14
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-51540CRITICALCVSS 9.8EG 9.82026-07-13
OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData).
- CVE-2026-53176CRITICALCVSS 9.8EG 9.82026-06-25
In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload length a…
- CVE-2026-37534CRITICALCVSS 9.8EG 9.82026-05-01
Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Transport_Protocol_Data_Transfer,allows attackers to write to arbitrary memory via crafted sequence numbe…
- CVE-2026-31883CRITICALCVSS 9.8EG 9.82026-03-13
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM and MS-ADPCM audio decoders leads to heap-buffer-overflow write via the RDPSND audio channel. In libfreerdp/codec/dsp.c, …
- CVE-2025-52471CRITICALCVSS 9.8EG 9.82025-06-24
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been identified in the ESP-NOW protocol implementation within the ESP Wi-Fi component of versions 5.4.1, 5.3.3, 5.2.5, and 5.1.…
- CVE-2025-30356CRITICALCVSS 9.8EG 9.82025-04-01
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In 1.3.3…
- CVE-2025-29913CRITICALCVSS 9.8EG 9.82025-03-17
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A critic…
- CVE-2025-29912CRITICALCVSS 9.8EG 9.82025-03-17
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versi…
- CVE-2025-29909CRITICALCVSS 9.8EG 9.82025-03-17
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versi…
- CVE-2024-47606CRITICALCVSS 9.8EG 9.82024-12-12
GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability occurs due to an underflow of the gint s…
- CVE-2018-9388CRITICALCVSS 9.8EG 9.82024-12-05
In store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing bounds checks or integer underflows. These could lead to escalation of privilege.
- CVE-2024-38063CRITICALCVSS 9.8EG 9.82024-08-13
Windows TCP/IP Remote Code Execution Vulnerability
- CVE-2024-38074CRITICALCVSS 9.8EG 9.82024-07-09
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- CVE-2024-23313CRITICALCVSS 9.8EG 9.82024-02-20
An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to an out-of-bounds write which in turn can lead t…
- CVE-2024-0808CRITICALCVSS 9.8EG 9.82024-01-24
Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
- CVE-2023-32653CRITICALCVSS 9.8EG 9.82023-09-25
An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to tri…
- CVE-2023-38427CRITICALCVSS 9.8EG 9.82023-07-18
An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts.
- CVE-2023-32014CRITICALCVSS 9.8EG 9.82023-06-14
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- CVE-2023-28250CRITICALCVSS 9.8EG 9.82023-04-11
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- CVE-2023-21708CRITICALCVSS 9.8EG 9.82023-03-14
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- CVE-2022-4338CRITICALCVSS 9.8EG 9.82023-01-10
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
- CVE-2021-40589CRITICALCVSS 9.8EG 9.82022-06-08
ZAngband zangband-data 2.7.5 is affected by an integer underflow vulnerability in src/tk/plat.c through the variable fileheader.bfOffBits.
- CVE-2021-33316CRITICALCVSS 9.8EG 9.82022-05-11
The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its lldp related component. Due to lack of proper validation on length field of ChassisID TLV,…
- CVE-2021-33315CRITICALCVSS 9.8EG 9.82022-05-11
The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This vulnerability exists in its lldp related component. Due to lack of proper validation on length field of PortID TLV, by…
- CVE-2021-1920CRITICALCVSS 9.8EG 9.82021-09-08
Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Sn…
- CVE-2021-1919CRITICALCVSS 9.8EG 9.82021-09-08
Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon …
- CVE-2021-21811CRITICALCVSS 9.8EG 9.82021-08-31
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger t…
- CVE-2021-28027CRITICALCVSS 9.8EG 9.82021-03-05
An issue was discovered in the bam crate before 0.1.3 for Rust. There is an integer underflow and out-of-bounds write during the loading of a bgzip block.
- CVE-2020-28194CRITICALCVSS 9.8EG 9.82021-02-01
Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker controls the RADIUS server, which can lead to arbitrary code…
- CVE-2020-3691CRITICALCVSS 9.8EG 9.82021-01-21
Possible out of bound memory access in audio due to integer underflow while processing modified contents in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, S…
- CVE-2020-3675CRITICALCVSS 9.8EG 9.82020-09-08
u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdrag…
- CVE-2020-15900CRITICALCVSS 9.8EG 9.82020-07-28
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too…
- CVE-2018-21065CRITICALCVSS 9.8EG 9.82020-04-08
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is an integer underflow in eCryptFS because of a missing size check. The Samsung ID is SVE-2017-11855 (August 2018).
- CVE-2019-20590CRITICALCVSS 9.8EG 9.82020-03-24
An issue was discovered on Samsung mobile devices with O(8.x) (Qualcomm chipsets) software. There is an integer underflow in the Secure Storage Trustlet. The Samsung ID is SVE-2019-13952 (July 2019).
- CVE-2019-14083CRITICALCVSS 9.8EG 9.82020-03-05
While parsing Service Descriptor Extended Attribute received as part of SDF frame, there is a possibility that incorrect length is specified in the attribute length field of extended SSI which can lead to integer underflow in Snapdragon Au…
- CVE-2019-16535CRITICALCVSS 9.8EG 9.82019-12-30
In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.
- CVE-2019-14532CRITICALCVSS 9.8EG 9.82019-08-02
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table.
- CVE-2019-14199CRITICALCVSS 9.8EG 9.82019-07-31
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an *udp_packet_handler call.
- CVE-2019-14192CRITICALCVSS 9.8EG 9.82019-07-31
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call.
- CVE-2019-2307CRITICALCVSS 9.8EG 9.82019-07-25
Possible integer underflow due to lack of validation before calculation of data length in 802.11 Rx management configuration in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial I…
Map vulnerabilities like CWE-191 to your infrastructure
EchelonGraph correlates every CVE — across CWE-191 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →