CWE-191— Integer Underflow
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.— MITRE CWE catalog
608 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-191page 4 of 13
- CVE-2026-3172HIGHCVSS 8.1EG 8.12026-02-25
Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server.
- CVE-2025-62291HIGHCVSS 8.1EG 8.12026-01-16
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
- CVE-2025-21376HIGHCVSS 8.1EG 8.12025-02-11
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- CVE-2024-32040HIGHCVSS 8.1EG 8.12024-04-22
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the `NSC` codec are vulnerable to integer underflow. Versio…
- CVE-2022-28733HIGHCVSS 8.1EG 8.12023-07-20
Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrap…
- CVE-2023-21556HIGHCVSS 8.1EG 8.12023-01-10
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
- CVE-2020-8174HIGHCVSS 8.1EG 8.12020-07-24
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
- CVE-2020-6096HIGHCVSS 8.1EG 8.12020-04-01
An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter …
- CVE-2018-16601HIGHCVSS 8.1EG 8.12018-12-06
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. A crafted IP header triggers a full memory space copy in prv…
- CVE-2026-68827HIGHCVSS 8.0EG 8.02026-09-08
Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.
- CVE-2026-25532HIGHCVSS 8.0EG 8.02026-02-04
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a vulnerability exists in the WPS (Wi-Fi Protected Setup) Enrollee implementation where malformed EAP-WSC packets w…
- CVE-2024-37986HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-37981HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-37975HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-37974HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2026-47585HIGHCVSS 7.8EG 7.82026-09-30
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation …
- CVE-2026-47540HIGHCVSS 7.8EG 7.82026-09-30
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of servic…
- CVE-2026-69687HIGHCVSS 7.8EG 7.82026-09-08
Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- CVE-2026-69421HIGHCVSS 7.8EG 7.82026-09-08
Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-69269HIGHCVSS 7.8EG 7.82026-09-08
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- CVE-2026-58087HIGHCVSS 7.8EG 7.82026-08-19
The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting the set, allocated a buffer sized for that count, and reacquired the lock. A sequence-number check was used to ve…
- CVE-2026-64909HIGHCVSS 7.8EG 7.82026-08-11
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-62741HIGHCVSS 7.8EG 7.82026-08-11
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- CVE-2026-63515HIGHCVSS 7.8EG 7.82026-08-11
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-62696HIGHCVSS 7.8EG 7.82026-08-11
Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-43628HIGHCVSS 7.8EG 7.82026-08-06
llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry_a…
- CVE-2026-64361HIGHCVSS 7.8EG 7.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length check_and_correct_requested_length() compares (off + len) against node_size using u32 arithmetic. Wh…
- CVE-2026-65704HIGHCVSS 7.8EG 7.82026-07-23
FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements pack…
- CVE-2026-55039HIGHCVSS 7.8EG 7.82026-07-14
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-50498HIGHCVSS 7.8EG 7.82026-07-14
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
- CVE-2026-50388HIGHCVSS 7.8EG 7.82026-07-14
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-50308HIGHCVSS 7.8EG 7.82026-07-14
Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.
- CVE-2026-49790HIGHCVSS 7.8EG 7.82026-07-14
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
- CVE-2026-55011HIGHCVSS 7.8EG 7.82026-07-14
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
- CVE-2026-53130HIGHCVSS 7.8EG 7.82026-06-24
In the Linux kernel, the following vulnerability has been resolved: fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START omfs_fill_super() rejects oversized s_sys_blocksize values (> PAGE_SIZE), but it does not reject values small…
- CVE-2026-52919HIGHCVSS 7.8EG 7.82026-06-24
In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix tp_meter counter underflow during shutdown batadv_tp_sender_shutdown() unconditionally decrements the "sending" atomic counter. If multiple paths (e.g. t…
- CVE-2026-42980HIGHCVSS 7.8EG 7.82026-06-09
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-45469HIGHCVSS 7.8EG 7.82026-06-09
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-46107HIGHCVSS 7.8EG 7.82026-05-28
In the Linux kernel, the following vulnerability has been resolved: dm-thin: fix metadata refcount underflow There's a bug in dm-thin in the function rebalance_children. If the internal btree node has one entry, the code tries to copy al…
- CVE-2026-25104HIGHCVSS 7.8EG 7.82026-05-26
A heap-based buffer overflow vulnerability exists in the LXF parsing functionality of MediaInfoLib (version(s): 26.01). A specially crafted .lxf file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger…
- CVE-2026-40397HIGHCVSS 7.8EG 7.82026-05-12
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-31656HIGHCVSS 7.8EG 7.82026-04-24
In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat A use-after-free / refcount underflow is possible when the heartbeat worker and intel_engine_park_hear…
- CVE-2026-33999HIGHCVSS 7.8EG 7.82026-04-23
A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to …
- CVE-2026-27297HIGHCVSS 7.8EG 7.82026-04-14
Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
- CVE-2026-27296HIGHCVSS 7.8EG 7.82026-04-14
Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
- CVE-2026-27907HIGHCVSS 7.8EG 7.82026-04-14
Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
- CVE-2026-3084HIGHCVSS 7.8EG 7.82026-03-16
GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to e…
- CVE-2026-32775HIGHCVSS 7.8EG 7.82026-03-16
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
- CVE-2026-20957HIGHCVSS 7.8EG 7.82026-01-13
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-61835HIGHCVSS 7.8EG 7.82025-11-11
Substance3D - Stager versions 3.1.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires u…
Map vulnerabilities like CWE-191 to your infrastructure
EchelonGraph correlates every CVE — across CWE-191 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →