CWE-191
493 CVEs • Abstraction: Base
Integer Underflow (Wrap or Wraparound)
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CVEs (493)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 5.net .net FrameworkVisual Studio 2017+2 moreJun 17, 2026 Sep 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Visual Studio Remote Code Execution Vulnerability |
1Microsoft 5.net .net FrameworkVisual Studio 2017+2 moreJun 17, 2026 Sep 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Visual Studio Remote Code Execution Vulnerability |
3Debian FedoraprojectFreerdp3Debian Linux FedoraFreerdpJun 17, 2026 Aug 31, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Integer-Underflow leading to Out-Of-Bound Read in the `zgfx_decompress_segment...Show more |
3Debian FedoraprojectFreerdp3Debian Linux FedoraFreerdpJun 17, 2026 Aug 31, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. This issue affects Clients only. Integer underflow leading to DOS (e.g. abort due to `WINPR_ASSERT` with default c...Show more |
1Microsoft 12Windows 10 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Aug 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
1Microsoft 11Windows 10 1507 Windows 10 1607Windows 10 1809+8 moreJun 17, 2026 Aug 8, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability |
Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len va...Show more |
2Linux Netapp5H300s H410sH500s+2 moreJun 17, 2026 Jul 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts. |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 Jul 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Excel Remote Code Execution Vulnerability |
An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a denial of service, such as an infinite loop. |
1Microsoft 3Odbc Driver For Sql Server Ole Db Driver For Sql ServerSql ServerJun 17, 2026 Jun 16, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft ODBC and OLE DB Remote Code Execution Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Jun 14, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2023.04, an attacker can send a crafted frame to the device resulti...Show more |
3Debian FedoraprojectMaradns3Debian Linux FedoraMaradnsJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packet decompression function allows an attac...Show more |
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device res...Show more |
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. An attacker can send a crafted frame to the device resulting in a large out of b...Show more |
1Qualcomm 42Qca6391 Firmware Qca6574 FirmwareQca6574a Firmware+39 moreJun 17, 2026 Apr 13, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal. |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreJun 17, 2026 Apr 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Integer Underflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the...Show more |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 20h2+9 moreJun 17, 2026 Apr 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Kernel Elevation of Privilege Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Apr 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Kernel Elevation of Privilege Vulnerability |