CWE-191
493 CVEs • Abstraction: Base
Integer Underflow (Wrap or Wraparound)
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CVEs (493)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreJun 17, 2026 Feb 11, 2022 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unpr...Show more |
1Microsoft 4Windows 10 Windows 11Windows Server+1 moreJun 17, 2026 Feb 9, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Named Pipe File System Elevation of Privilege Vulnerability |
2Fedoraproject Neutrinolabs2Fedora XrdpJun 17, 2026 Feb 7, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Jan 25, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mappings for the case where a PV guest would have the IOMMU enabled. PV guests can request two forms of map...Show more |
Frontier is Substrate's Ethereum compatibility layer. Prior to commit number `8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664`, a bug in Frontier's MODEXP precompile implementation can cause an integer underflow in certain cond...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
4Asterisk DebianSangoma+1 more4Asterisk Certified AsteriskDebian Linux+1 moreJun 17, 2026 Dec 22, 2021 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message c...Show more |
Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in...Show more |
1Mitsubishielectric 3Ezsocket Gx Works2Melsoft NavigatorJun 17, 2026 Dec 17, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Integer Underflow vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.4 and prior allows an...Show more |
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating...Show more |
1Siemens 10Apogee Modular Building Controller Firmware Apogee Modular Equiment Controller FirmwareApogee Pxc Compact Firmware+7 moreJun 17, 2026 Nov 9, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions...Show more |
TensorFlow is an open source platform for machine learning. In affected versions the Keras pooling layers can trigger a segfault if the size of the pool is 0 or if a dimension is negative. This is due to the TensorFlow's...Show more |
Integer Underflow in 6LoWPAN IPHC Header Uncompression in Zephyr. Zephyr versions >= >=2.4.0 contain Integer Underflow (Wrap or Wraparound) (CWE-191). For more information, see https://github.com/zephyrproject-rtos/zephy...Show more |
Integer Underflow in Zephyr in IEEE 802154 Fragment Reassembly Header Removal. Zephyr versions >= >=2.4.0 contain Integer Overflow to Buffer Overflow (CWE-680). For more information, see https://github.com/zephyrproject-...Show more |
Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager. |
3Debian FedoraprojectRibbonsoft4Debian Linux DxflibExtra Packages For Enterprise Linux+1 moreJun 17, 2026 Sep 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious f...Show more |
1Qualcomm 171Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+168 moreJun 17, 2026 Sep 8, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdrago...Show more |
1Qualcomm 155Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+152 moreJun 17, 2026 Sep 8, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdrag...Show more |
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious...Show more |
1Nvidia 2Jetson Linux Shield ExperienceJun 17, 2026 Aug 11, 2021 N/A· v4 7.3 HIGH· v3 4.6 MEDIUM· v2 NVIDIA Linux kernel distributions contain a vulnerability in FuSa Capture (VI/ISP), where integer underflow due to lack of input validation may lead to complete denial of service, partial integrity, and serious confident...Show more |