CWE-191— Integer Underflow
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.— MITRE CWE catalog
608 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-191page 12 of 13
- CVE-2026-6678MEDIUMCVSS 5.3EG 5.32026-06-25
Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.
- CVE-2026-8463MEDIUMCVSS 5.3EG 5.32026-05-13
Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty encoded input. The auto-detect form of argon2_verify passes encoded_len - 1 as the length argument to memchr without check…
- CVE-2026-7423MEDIUMCVSS 5.3EG 5.32026-04-29
Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing ping support is enabled, because header si…
- CVE-2026-34064MEDIUMCVSS 5.3EG 5.32026-04-22
nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingContract::can_change_balance` returns `AccountError::InsufficientFunds` when `new_balance < min_cap`, but it constructs th…
- CVE-2026-33899MEDIUMCVSS 5.3EG 5.32026-04-13
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds.…
- CVE-2026-1005MEDIUMCVSS 5.3EG 5.32026-03-19
Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authentication tag into traffic inspected by ssl_Dec…
- CVE-2025-10933MEDIUMCVSS 5.3EG 5.32026-01-05
An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads.
- CVE-2025-62567MEDIUMCVSS 5.3EG 5.32025-12-09
Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.
- CVE-2024-52558MEDIUMCVSS 5.3EG 5.32024-12-06
The affected product is vulnerable to an integer underflow. An unauthenticated attacker could send a malformed HTTP request, which could allow the attacker to crash the program.
- CVE-2023-40181MEDIUMCVSS 5.3EG 5.32023-08-31
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Integer-Underflow leading to Out-Of-Bound Read in the `zgfx_decompress_segment` function. In the …
- CVE-2020-24370MEDIUMCVSS 5.3EG 5.32020-08-17
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
- CVE-2020-11909MEDIUMCVSS 5.3EG 5.32020-06-17
The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow.
- CVE-2026-49282MEDIUMCVSS 5.1EG 5.12026-08-14
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before indexin…
- CVE-2026-42326MEDIUMCVSS 5.1EG 5.12026-05-18
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when writing an IPTC output file a malicious input file could cause an out of bounds read of a single …
- CVE-2026-17504MEDIUMCVSS 4.4EG 5.12026-09-24
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime. An attacker with root access to a…
- CVE-2026-11850MEDIUMCVSS 5.0EG 5.02026-06-11
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_l…
- CVE-2026-34165MEDIUMCVSS 5.0EG 5.02026-03-31
go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, poten…
- CVE-2026-27710MEDIUMCVSS 5.0EG 5.02026-02-26
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a denial-of-service vulnerability exists in NanaZip’s `.NET Single File Application` parser. A crafted bundle can for…
- CVE-2014-8768MEDIUMCVSS v2 5.0EG 5.02014-11-20
Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame.
- CVE-2013-6425MEDIUMCVSS v2 5.0EG 5.02014-01-18
Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
- CVE-2013-6424MEDIUMCVSS v2 5.0EG 5.02014-01-18
Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
- CVE-2004-0184MEDIUMCVSS v2 5.0EG 5.02004-05-04
Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte orde…
- CVE-2020-2031MEDIUMCVSS 4.9EG 4.92020-07-08
An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated administrators to issue a command from the command line interface that causes the component to stop responding. Repeated …
- CVE-2026-22185MEDIUMCVSS 4.6EG 4.62026-01-07
OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded N…
- CVE-2017-8924MEDIUMCVSS 4.6EG 4.62017-05-12
The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted …
- CVE-2026-81881MEDIUMCVSS 4.4EG 4.42026-09-22
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata sectio…
- CVE-2026-26204MEDIUMCVSS 4.4EG 4.42026-04-29
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to before version 4.14.4, a heap-based out-of-bounds WRITE occurs in GetAlertData, resulting in writing a NULL byte exactly 1 …
- CVE-2025-23335MEDIUMCVSS 4.4EG 4.42025-08-06
NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain a vulnerability where an attacker could cause an underflow by a specific model configuration and a specific input. A successful exploit of this vulnerab…
- CVE-2023-20635MEDIUMCVSS 4.4EG 4.42023-03-07
In keyinstall, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0…
- CVE-2026-62289MEDIUMCVSS 4.3EG 4.32026-08-18
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_handle…
- CVE-2024-50597MEDIUMCVSS 4.3EG 4.32025-04-02
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet …
- CVE-2024-50596MEDIUMCVSS 4.3EG 4.32025-04-02
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet …
- CVE-2024-50595MEDIUMCVSS 4.3EG 4.32025-04-02
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a seque…
- CVE-2024-50594MEDIUMCVSS 4.3EG 4.32025-04-02
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a seque…
- CVE-2025-2581MEDIUMCVSS 4.3EG 4.32025-03-21
A vulnerability has been found in xmedcon 0.25.0 and classified as problematic. Affected by this vulnerability is the function malloc of the component DICOM File Handler. The manipulation leads to integer underflow. The attack can be launc…
- CVE-2024-49103MEDIUMCVSS 4.3EG 4.32024-12-12
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
- CVE-2024-20474MEDIUMCVSS 4.3EG 4.32024-10-23
A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due t…
- CVE-2024-5256MEDIUMCVSS 4.3EG 4.32024-06-06
Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos Era 100 smart speakers. A…
- CVE-2026-40386MEDIUMCVSS 4.0EG 4.02026-04-12
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.
- CVE-2026-39314MEDIUMCVSS 4.0EG 4.02026-04-07
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, an integer underflow vulnerability in _ppdCreateFromIPP() (cups/ppd-cache.c) allows any unprivileged local u…
- CVE-2026-44069LOWCVSS 3.9EG 3.92026-05-21
An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a minor service disruption via crafted volume translation input.
- CVE-2026-16241LOWCVSS 3.8EG 3.82026-08-13
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region …
- CVE-2026-40955LOWCVSS 3.7EG 3.72026-07-15
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS a…
- CVE-2026-40954LOWCVSS 3.7EG 3.72026-07-15
CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS a…
- CVE-2026-23748LOWCVSS 3.7EG 3.72026-02-26
Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit d7f55b38, contain an out-of-bounds read in LightDB State string parsing. When processing a string payload, a payload_size value less than 2 can cause a size_t underflow…
- CVE-2026-95958LOWCVSS 3.3EG 3.32026-09-23
A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing a manipulation of the argument BlockSize results in integer…
- CVE-2023-28902LOWCVSS 3.3EG 3.32025-06-28
An integer underflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause denial-of-service of the infotainment system. The vulnerability was originally discovered in Sko…
- CVE-2025-26269LOWCVSS 3.3EG 3.32025-04-17
DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.
- CVE-2020-14378LOWCVSS 3.3EG 3.32020-09-30
An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294…
- CVE-2026-29776LOWCVSS 3.1EG 3.12026-03-13
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library This vulnerability is fixed in 3.24.0.
Map vulnerabilities like CWE-191 to your infrastructure
EchelonGraph correlates every CVE — across CWE-191 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →