CWE-191— Integer Underflow
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.— MITRE CWE catalog
608 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-191page 3 of 13
- CVE-2024-24474HIGHCVSS 8.8EG 8.82024-02-20
QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is less than the length of the available FIFO data. This occurs in esp_do_nodma in hw/scsi/esp.c because o…
- CVE-2023-5753HIGHCVSS 8.8EG 8.82023-10-25
Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c
- CVE-2023-35387HIGHCVSS 8.8EG 8.82023-08-08
Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability
- CVE-2023-24887HIGHCVSS 8.8EG 8.82023-04-11
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-24864HIGHCVSS 8.8EG 8.82023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Elevation of Privilege Vulnerability
- CVE-2023-21684HIGHCVSS 8.8EG 8.82023-02-14
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-21681HIGHCVSS 8.8EG 8.82023-01-10
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- CVE-2022-24046HIGHCVSS 8.8EG 8.82022-02-18
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems). Authentication is not required to exploit th…
- CVE-2021-4066HIGHCVSS 8.8EG 8.82021-12-23
Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-43083HIGHCVSS 8.8EG 8.82021-12-19
Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit th…
- CVE-2021-21897HIGHCVSS 8.8EG 8.82021-09-08
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this…
- CVE-2021-20240HIGHCVSS 8.8EG 8.82021-05-28
A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code o…
- CVE-2020-1239HIGHCVSS 8.8EG 8.82020-06-09
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1238.
- CVE-2017-18170HIGHCVSS 8.8EG 8.82018-10-23
Improper input validation in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, S…
- CVE-2018-14325HIGHCVSS 8.8EG 8.82018-07-16
In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.
- CVE-2017-14796HIGHCVSS 8.8EG 8.82017-09-28
The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (integer underflow and application crash) or possibly have unspecified other impact via a crafted BPG file, related to improper …
- CVE-2019-5144HIGHCVSS 8.1EG 8.82019-12-12
An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Software SDK 7.10.2. A specially crafted jp2 file can cause a heap overflow, which can result in remote code execution. An a…
- CVE-2022-2869HIGHCVSS 5.5EG 8.82022-08-17
libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a u…
- CVE-2022-2867HIGHCVSS 5.5EG 8.82022-08-17
libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a…
- CVE-2026-86537HIGHCVSS 8.7EG 8.72026-10-02
Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recomme…
- CVE-2026-9624HIGHCVSS 8.7EG 8.72026-09-01
A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover.
- CVE-2026-9622HIGHCVSS 8.7EG 8.72026-09-01
A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.
- CVE-2026-19314HIGHCVSS 8.7EG 8.72026-08-27
An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
- CVE-2026-19317HIGHCVSS 8.7EG 8.72026-08-27
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
- CVE-2026-78011HIGHCVSS 8.7EG 8.72026-08-27
An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
- CVE-2026-43916HIGHCVSS 8.7EG 8.72026-05-12
pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior to 0.2.0-alpha, a heap buffer over-read in peer_lookup_tcp (src/peer_lookup.c:134, prior to the fix) allowed a crafted…
- CVE-2022-39293HIGHCVSS 8.6EG 8.62022-10-13
Azure RTOS USBX is a high-performance USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. The case is, in [_ux_host_class_pima_read](https://github.com/azure-rtos/usbx/blob/master/common/…
- CVE-2017-14496HIGHCVSS 7.5EG 8.52017-10-03
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
- CVE-2026-45463HIGHCVSS 8.4EG 8.42026-06-09
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2024-54028HIGHCVSS 8.4EG 8.42025-06-02
An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this …
- CVE-2018-5852HIGHCVSS 8.4EG 8.42024-11-26
An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'
- CVE-2023-21630HIGHCVSS 8.4EG 8.42023-04-13
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
- CVE-2023-31102HIGHCVSS 7.8EG 8.42023-11-03
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
- CVE-2023-21815HIGHCVSS 7.8EG 8.42023-02-14
Visual Studio Remote Code Execution Vulnerability
- CVE-2021-3323HIGHCVSS 8.3EG 8.32021-10-12
Integer Underflow in 6LoWPAN IPHC Header Uncompression in Zephyr. Zephyr versions >= >=2.4.0 contain Integer Underflow (Wrap or Wraparound) (CWE-191). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisori…
- CVE-2011-2497HIGHCVSS v2 8.3EG 8.32011-08-29
Integer underflow in the l2cap_config_req function in net/bluetooth/l2cap_core.c in the Linux kernel before 3.0 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a s…
- CVE-2026-82459HIGHCVSS 8.2EG 8.22026-10-02
Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes …
- CVE-2026-17485HIGHCVSS 8.2EG 8.22026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.
- CVE-2026-54412HIGHCVSS 8.2EG 8.22026-06-14
LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or…
- CVE-2026-54413HIGHCVSS 8.2EG 8.22026-06-14
driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially…
- CVE-2025-1924HIGHCVSS 8.2EG 8.22026-02-13
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receive maliciously crafted packets, a DoS attack may cause Vnet/IP communication functions to stop or arbitrary pro…
- CVE-2025-11931HIGHCVSS 8.2EG 8.22025-11-21
Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCha20Poly1305_Decrypt() which is not used with TLS connections, only from direct calls from an…
- CVE-2025-3947HIGHCVSS 8.2EG 8.22025-07-10
The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to Input Data Manipulation, which could result in i…
- CVE-2020-17395HIGHCVSS 8.2EG 8.22020-08-25
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploi…
- CVE-2026-19186HIGHCVSS 8.1EG 8.12026-10-07
ieee802154_decipher_data_frame() in subsys/net/l2/ieee802154/ieee802154_frame.c computed payload_len = net_pkt_get_len(pkt) - ll_hdr_len - authtag_len without first checking that the received frame is at least ll_hdr_len + authtag_len byte…
- CVE-2026-13308HIGHCVSS 8.1EG 8.12026-07-29
Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers…
- CVE-2026-53178HIGHCVSS 8.1EG 8.12026-06-25
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction Add guards to ensure ie_length is large enough before subtracting fixed IE offsets to preven…
- CVE-2026-42981HIGHCVSS 8.1EG 8.12026-06-09
Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.
- CVE-2026-7424HIGHCVSS 8.1EG 8.12026-04-29
Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of …
- CVE-2026-5188HIGHCVSS 8.1EG 8.12026-04-10
An integer underflow issue exists in wolfSSL when parsing the Subject Alternative Name (SAN) extension of X.509 certificates. A malformed certificate can specify an entry length larger than the enclosing sequence, causing the internal leng…
Map vulnerabilities like CWE-191 to your infrastructure
EchelonGraph correlates every CVE — across CWE-191 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →