CWE-191
493 CVEs • Abstraction: Base
Integer Underflow (Wrap or Wraparound)
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CVEs (493)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DpdkOpensuse3Data Plane Development Kit LeapUbuntu LinuxJun 17, 2026 Sep 30, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to g...Show more |
3Canonical RedhatX.org3Enterprise Linux Ubuntu LinuxX ServerJun 17, 2026 Sep 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data...Show more |
3Canonical RedhatX.org3Enterprise Linux Ubuntu LinuxX ServerJun 17, 2026 Sep 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data...Show more |
3Canonical RedhatX.org3Enterprise Linux Ubuntu LinuxX ServerJun 17, 2026 Sep 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerabili...Show more |
1Qualcomm 50Apq8053 Firmware Apq8096au FirmwareApq8098 Firmware+47 moreJun 17, 2026 Sep 9, 2020 N/A· v4 9.1 CRITICAL· v3 9.4 HIGH· v2 u'Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, S...Show more |
1Qualcomm 19Ipq5018 Firmware Ipq6018 FirmwareIpq8074 Firmware+16 moreJun 17, 2026 Sep 8, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Con...Show more |
In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leading to heap buffer overflow. This can cause an application crash or on so...Show more |
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system...Show more |
3Debian FedoraprojectLua3Debian Linux FedoraLuaJun 17, 2026 Aug 17, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31). |
An exploitable denial of service vulnerability exists in the freeDiameter functionality of freeDiameter 1.3.2. A specially crafted Diameter request can trigger a memory corruption resulting in denial-of-service. An attac...Show more |
3Artifex CanonicalOpensuse3Ghostscript LeapUbuntu LinuxJun 17, 2026 Jul 28, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in...Show more |
3Netapp NodejsOracle9Active Iq Unified Manager Banking Extensibility WorkbenchBlockchain Platform+6 moreJun 17, 2026 Jul 24, 2020 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0. |
2Opensuse Oracle2Leap Vm VirtualboxJun 17, 2026 Jul 15, 2020 N/A· v4 7.5 HIGH· v3 4.4 MEDIUM· v2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerabil...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jul 14, 2020 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1...Show more |
An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated administrators to issue a command from the command line interface that causes the component to stop re...Show more |
The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow. |
The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow. |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jun 9, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1238. |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Apr 24, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the lower filesystem without taking an additi...Show more |
2Contiki Ng Contiki Os2Contiki Contiki Ng.Jun 17, 2026 Apr 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. A buffer overflow is present due to an integer underflow during 6LoWPAN fragment processing in the face of truncated fragments in os/net/ipv6/sic...Show more |