CWE-191— Integer Underflow
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.— MITRE CWE catalog
608 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-191page 5 of 13
- CVE-2025-61836HIGHCVSS 7.8EG 7.82025-11-11
Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires us…
- CVE-2025-61826HIGHCVSS 7.8EG 7.82025-11-11
Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires us…
- CVE-2025-59242HIGHCVSS 7.8EG 7.82025-10-14
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2025-47130HIGHCVSS 7.8EG 7.82025-07-08
Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi…
- CVE-2025-47128HIGHCVSS 7.8EG 7.82025-07-08
Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi…
- CVE-2025-47097HIGHCVSS 7.8EG 7.82025-07-08
InCopy versions 20.3, 19.5.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user int…
- CVE-2025-49532HIGHCVSS 7.8EG 7.82025-07-08
Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires u…
- CVE-2025-47136HIGHCVSS 7.8EG 7.82025-07-08
InDesign Desktop versions 19.5.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
- CVE-2025-47996HIGHCVSS 7.8EG 7.82025-07-08
Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-43555HIGHCVSS 7.8EG 7.82025-05-13
Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
- CVE-2025-43546HIGHCVSS 7.8EG 7.82025-05-13
Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user i…
- CVE-2025-30324HIGHCVSS 7.8EG 7.82025-05-13
Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi…
- CVE-2025-30296HIGHCVSS 7.8EG 7.82025-04-08
Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi…
- CVE-2025-21160HIGHCVSS 7.8EG 7.82025-02-11
Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires use…
- CVE-2025-21156HIGHCVSS 7.8EG 7.82025-02-11
InCopy versions 20.0, 19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user int…
- CVE-2025-21158HIGHCVSS 7.8EG 7.82025-02-11
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue req…
- CVE-2025-21135HIGHCVSS 7.8EG 7.82025-01-14
Animate versions 24.0.6, 23.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user …
- CVE-2025-21134HIGHCVSS 7.8EG 7.82025-01-14
Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires us…
- CVE-2025-21133HIGHCVSS 7.8EG 7.82025-01-14
Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires us…
- CVE-2025-21122HIGHCVSS 7.8EG 7.82025-01-14
Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue require…
- CVE-2024-53955HIGHCVSS 7.8EG 7.82024-12-10
Bridge versions 14.1.3, 15.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user int…
- CVE-2024-53954HIGHCVSS 7.8EG 7.82024-12-10
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user …
- CVE-2024-52989HIGHCVSS 7.8EG 7.82024-12-10
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user …
- CVE-2024-52987HIGHCVSS 7.8EG 7.82024-12-10
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user …
- CVE-2024-52986HIGHCVSS 7.8EG 7.82024-12-10
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user …
- CVE-2024-52985HIGHCVSS 7.8EG 7.82024-12-10
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user …
- CVE-2024-52984HIGHCVSS 7.8EG 7.82024-12-10
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user …
- CVE-2024-54095HIGHCVSS 7.8EG 7.82024-12-10
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 10). The affected application is vulnerable to integer underflow vulnerability which can be triggered while parsing specially crafted PAR files. This co…
- CVE-2024-11477HIGHCVSS 7.8EG 7.82024-11-22
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to expl…
- CVE-2024-53061HIGHCVSS 7.8EG 7.82024-11-19
In the Linux kernel, the following vulnerability has been resolved: media: s5p-jpeg: prevent buffer overflows The current logic allows word to be less than 2. If this happens, there will be buffer overflows, as reported by smatch. Add ex…
- CVE-2024-49514HIGHCVSS 7.8EG 7.82024-11-12
Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi…
- CVE-2024-47425HIGHCVSS 7.8EG 7.82024-10-09
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi…
- CVE-2024-46759HIGHCVSS 7.8EG 7.82024-09-18
In the Linux kernel, the following vulnerability has been resolved: hwmon: (adc128d818) Fix underflows seen when writing limit attributes DIV_ROUND_CLOSEST() after kstrtol() results in an underflow if a large negative number such as -922…
- CVE-2024-41857HIGHCVSS 7.8EG 7.82024-09-13
Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires use…
- CVE-2024-38517HIGHCVSS 7.8EG 7.82024-07-09
Tencent RapidJSON is vulnerable to privilege escalation due to an integer underflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a…
- CVE-2024-38050HIGHCVSS 7.8EG 7.82024-07-09
Windows Workstation Service Elevation of Privilege Vulnerability
- CVE-2024-26913HIGHCVSS 7.8EG 7.82024-04-17
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dcn35 8k30 Underflow/Corruption Issue [why] odm calculation is missing for pipe split policy determination and cause Underflow/Corruption issue. [h…
- CVE-2024-21309HIGHCVSS 7.8EG 7.82024-01-09
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
- CVE-2023-33059HIGHCVSS 7.8EG 7.82023-11-07
Memory corruption in Audio while processing the VOC packet data from ADSP.
- CVE-2023-36785HIGHCVSS 7.8EG 7.82023-10-10
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2023-36796HIGHCVSS 7.8EG 7.82023-09-12
Visual Studio Remote Code Execution Vulnerability
- CVE-2023-36794HIGHCVSS 7.8EG 7.82023-09-12
Visual Studio Remote Code Execution Vulnerability
- CVE-2023-33158HIGHCVSS 7.8EG 7.82023-07-11
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2023-29349HIGHCVSS 7.8EG 7.82023-06-16
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
- CVE-2023-26421HIGHCVSS 7.8EG 7.82023-04-12
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Integer Underflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Expl…
- CVE-2023-28293HIGHCVSS 7.8EG 7.82023-04-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-28272HIGHCVSS 7.8EG 7.82023-04-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-21718HIGHCVSS 7.8EG 7.82023-02-14
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2022-27492HIGHCVSS 7.8EG 7.82022-09-23
An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file.
- CVE-2022-22715HIGHCVSS 7.8EG 7.82022-02-09
Named Pipe File System Elevation of Privilege Vulnerability
Map vulnerabilities like CWE-191 to your infrastructure
EchelonGraph correlates every CVE — across CWE-191 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →