CWE-191
493 CVEs • Abstraction: Base
Integer Underflow (Wrap or Wraparound)
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CVEs (493)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wa...Show more |
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a n...Show more |
CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a n...Show more |
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application,...Show more |
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application,...Show more |
1Microsoft 7365 Apps ExcelMicrosoft 365+4 moreJul 16, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 21, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 22, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. |
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 20, 2026 Jul 14, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 22, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally. |
1Microsoft 11Windows 10 1607 Windows 10 1809Windows 10 21h2+8 moreJul 22, 2026 Jul 14, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJul 20, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
1Microsoft 7Windows 10 1607 Windows 10 1809Windows Server 2012+4 moreJul 20, 2026 Jul 14, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network. |
OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData). |
U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK...Show more |
OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash th...Show more |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority following a notification that the vulnerability determination was made in error. After review, the CNA confirmed the erroneous fi...Show more |
2Gnome Redhat2Enterprise Linux GlibJul 21, 2026 Jun 30, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested...Show more |
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation u...Show more |