CWE-191
493 CVEs • Abstraction: Base
Integer Underflow (Wrap or Wraparound)
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CVEs (493)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Apr 11, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
1Microsoft 4Windows Server 2012 Windows Server 2016Windows Server 2019+1 moreJun 17, 2026 Apr 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Network File System Information Disclosure Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Apr 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability |
1Microsoft 11Windows 10 1607 Windows 10 1809Windows 10 20h2+8 moreJun 17, 2026 Mar 14, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Mar 14, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft PostScript and PCL6 Class Printer Driver Elevation of Privilege Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Mar 14, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Remote Procedure Call Runtime Remote Code Execution Vulnerability |
In keyinstall, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitati...Show more |
1Microsoft 3Visual Studio 2017 Visual Studio 2019Visual Studio 2022Jun 17, 2026 Feb 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Visual Studio Remote Code Execution Vulnerability |
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Feb 14, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability |
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services. |
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service. |
1Microsoft 15Windows 10 1607 Windows 10 1809Windows 10 20h2+12 moreJun 17, 2026 Jan 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
1Microsoft 15Windows 10 1607 Windows 10 1809Windows 10 20h2+12 moreJun 17, 2026 Jan 10, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability |
1Microsoft 15Windows 10 1607 Windows 10 1809Windows 10 20h2+12 moreJun 17, 2026 Jan 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows iSCSI Service Denial of Service Vulnerability |
2Debian Openvswitch2Debian Linux OpenvswitchJun 17, 2026 Jan 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch. |
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services. |
In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User i...Show more |
In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds reads due to integer overflows. This could lead to remote information disclosure with no additional exe...Show more |
1Schneider Electric 48Modicon M340 Bmx P34 2010 Firmware Modicon M340 Bmx P34 2030 FirmwareModicon M580 Bmeh582040 Firmware+45 moreJun 17, 2026 Nov 22, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon...Show more |