CWE-191— Integer Underflow
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.— MITRE CWE catalog
608 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-191page 9 of 13
- CVE-2026-18747MEDIUMCVSS 6.8EG 6.82026-09-28
The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len -= 2U; in mcumgr_serial_process_frag() (subsys/mgmt/m…
- CVE-2026-28525MEDIUMCVSS 6.8EG 6.82026-04-23
SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_multipart.c that allows unauthenticated attackers to cause a denial of service by sending a crafted HTTP POST request to /upload with a malform…
- CVE-2024-49077MEDIUMCVSS 6.8EG 6.82024-12-12
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability
- CVE-2024-6258MEDIUMCVSS 6.8EG 6.82024-09-13
BT: Missing length checks of net_buf in rfcomm_handle_data
- CVE-2024-3077MEDIUMCVSS 6.8EG 6.82024-03-29
An malicious BLE device can crash BLE victim device by sending malformed gatt packet
- CVE-2011-4031MEDIUMCVSS v2 6.8EG 6.82012-05-09
Integer underflow in the asfrtp_parse_packet function in libavformat/rtpdec_asf.c in FFmpeg before 0.8.3 allows remote attackers to execute arbitrary code via a crafted ASF packet.
- CVE-2010-2497MEDIUMCVSS v2 6.8EG 6.82010-08-19
Integer underflow in glyph handling in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
- CVE-2024-26828MEDIUMCVSS 6.7EG 6.72024-04-17
In the Linux kernel, the following vulnerability has been resolved: cifs: fix underflow in parse_server_interfaces() In this loop, we step through the buffer and after each item we check if the size_left is greater than the minimum size …
- CVE-2022-30787MEDIUMCVSS 6.7EG 6.72022-05-26
An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
- CVE-2026-73433MEDIUMCVSS 6.6EG 6.62026-08-12
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficien…
- CVE-2022-20073MEDIUMCVSS 6.6EG 6.62022-04-11
In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed…
- CVE-2026-106429MEDIUMCVSS 6.5EG 6.52026-10-08
An integer underflow in the KMS endpoint-parsing logic of MongoDB libmongocrypt can cause an allocation failure that terminates the application process. This can occur when an authenticated user modifies a key document in the key vault col…
- CVE-2026-102168MEDIUMCVSS 6.5EG 6.52026-10-06
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial …
- CVE-2026-44235MEDIUMCVSS 6.5EG 6.52026-09-17
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabbit…
- CVE-2026-78453MEDIUMCVSS 6.5EG 6.52026-09-08
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.
- CVE-2026-82250MEDIUMCVSS 6.5EG 6.52026-08-28
gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band packet t…
- CVE-2026-18728MEDIUMCVSS 6.5EG 6.52026-08-13
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to caus…
- CVE-2026-18727MEDIUMCVSS 6.5EG 6.52026-08-12
A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6 Advertis…
- CVE-2026-62814MEDIUMCVSS 6.5EG 6.52026-08-11
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- CVE-2026-62714MEDIUMCVSS 6.5EG 6.52026-08-11
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- CVE-2026-62720MEDIUMCVSS 6.5EG 6.52026-08-11
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- CVE-2026-62745MEDIUMCVSS 6.5EG 6.52026-08-11
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- CVE-2026-62742MEDIUMCVSS 6.5EG 6.52026-08-11
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- CVE-2026-62716MEDIUMCVSS 6.5EG 6.52026-08-11
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- CVE-2026-62715MEDIUMCVSS 6.5EG 6.52026-08-11
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- CVE-2026-62718MEDIUMCVSS 6.5EG 6.52026-08-11
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- CVE-2026-70633MEDIUMCVSS 6.5EG 6.52026-08-06
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator that allows authenticated attackers to cause a denial of service by storing a crafted compres…
- CVE-2026-24077MEDIUMCVSS 6.5EG 6.52026-08-04
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
- CVE-2026-44251MEDIUMCVSS 6.5EG 6.52026-07-17
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash …
- CVE-2026-55490MEDIUMCVSS 6.5EG 6.52026-07-07
OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending…
- CVE-2026-58058MEDIUMCVSS 6.5EG 6.52026-06-28
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a larg…
- CVE-2026-11789MEDIUMCVSS 6.5EG 6.52026-06-09
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP …
- CVE-2026-35049MEDIUMCVSS 6.5EG 6.52026-06-02
wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external message with an encrypted payload that is shorter than 16 bytes, the Wire iOS client crashes.…
- CVE-2026-41499MEDIUMCVSS 6.5EG 6.52026-04-29
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, multiple heap-based out-of-bounds WRITE vulnerabilities exist in parse_uname_string() (remoted_op.c)…
- CVE-2026-6914MEDIUMCVSS 6.5EG 6.52026-04-29
Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server. This issue affects all MongoDB Server v8.2 versions, all MongoDB Server v8.1 versions, MongoDB Server v8.0 ve…
- CVE-2026-5778MEDIUMCVSS 6.5EG 6.52026-04-09
Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authentication tag into traffic inspected by ssl_Decod…
- CVE-2025-48021MEDIUMCVSS 6.5EG 6.52026-02-13
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and ve…
- CVE-2025-30668MEDIUMCVSS 6.5EG 6.52025-05-14
Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.
- CVE-2024-21466MEDIUMCVSS 6.5EG 6.52024-07-01
Information disclosure while parsing sub-IE length during new IE generation.
- CVE-2024-30011MEDIUMCVSS 6.5EG 6.52024-05-14
Windows Hyper-V Denial of Service Vulnerability
- CVE-2023-36909MEDIUMCVSS 6.5EG 6.52023-08-08
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- CVE-2022-3165MEDIUMCVSS 6.5EG 6.52022-10-17
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, re…
- CVE-2021-25121MEDIUMCVSS 6.5EG 6.52022-06-20
The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service on the post/page when a user submit such rating
- CVE-2022-21685MEDIUMCVSS 6.5EG 6.52022-01-14
Frontier is Substrate's Ethereum compatibility layer. Prior to commit number `8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664`, a bug in Frontier's MODEXP precompile implementation can cause an integer underflow in certain conditions. This will c…
- CVE-2021-24894MEDIUMCVSS 6.5EG 6.52021-11-23
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews ar…
- CVE-2021-41821MEDIUMCVSS 6.5EG 6.52021-09-29
Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.
- CVE-2017-14997MEDIUMCVSS 6.5EG 6.52017-10-04
GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c.
- CVE-2023-24911MEDIUMCVSS 4.3EG 6.52023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- CVE-2026-94090MEDIUMCVSS 6.3EG 6.32026-09-20
A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the component PE Parser. The manipulation of the argument misc.Length results in integer …
- CVE-2020-11906MEDIUMCVSS 6.3EG 6.32020-06-17
The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.
Map vulnerabilities like CWE-191 to your infrastructure
EchelonGraph correlates every CVE — across CWE-191 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →