CWE-191
493 CVEs • Abstraction: Base
Integer Underflow (Wrap or Wraparound)
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CVEs (493)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianOpensuse+1 more5Backports Sle Debian LinuxLeap+2 moreJun 17, 2026 Jul 14, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly...Show more |
1Cisco 2Integrated Management Controller Unified Computing SystemJun 17, 2026 Jun 20, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition on an affected d...Show more |
2Redhat Tuxera6Enterprise Linux Enterprise Linux EusEnterprise Linux Server+3 moreJun 17, 2026 Jun 5, 2019 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer o...Show more |
1Qualcomm 41Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+38 moreJun 17, 2026 May 24, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Possible integer underflow can happen when calculating length of elementary stream map from invalid packet length which is later used to read from input buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv...Show more |
1Qualcomm 41Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+38 moreJun 17, 2026 May 24, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Possible integer underflow can happen when calculating length of elementary stream info from invalid section length which is later used to read from input buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect...Show more |
1Qualcomm 31Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+28 moreNov 21, 2024 May 24, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Improper input validation on input data which is used to locate and copy the additional IEs in WLAN function can lead to potential integer truncation issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT,...Show more |
An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the er...Show more |
1Qualcomm 17Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+14 moreNov 21, 2024 May 6, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An integer underflow may occur due to lack of check when received data length from font_mgr_qsee_request_service is bigger than the minimal value of the segment header, which may result in a buffer overflow, in Snapdrago...Show more |
2Fedoraproject Kmplayer2Fedora KmplayerJun 17, 2026 Apr 9, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer underflow then to memory out-of-bound read/write. An attacker can exploit t...Show more |
An exploitable integer underflow vulnerability exists in the mdnscap binary of the CUJO Smart Firewall, version 7003. When parsing SRV records in an mDNS packet, the "RDLENGTH" value is handled incorrectly, leading to an...Show more |
2Debian Rdesktop2Debian Linux RdesktopNov 21, 2024 Mar 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process() and results in memory corruption and probably even a remote code exe...Show more |
2Debian Rdesktop2Debian Linux RdesktopNov 21, 2024 Mar 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably even a remote code ex...Show more |
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_process() and results in memory corruption and probably even a remote code execut...Show more |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. A crafted IP header triggers a full memor...Show more |
1Qualcomm 25Qca9379 Firmware Sd 205 FirmwareSd 210 Firmware+22 moreNov 21, 2024 Oct 23, 2018 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Improper input validation in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/1...Show more |
1Cisco 5Webex Business Suite 31 Webex Business Suite 32Webex Business Suite 33+2 moreNov 21, 2024 Oct 5, 2018 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilit...Show more |
1Atlantiswordprocessor 1Atlantis Word Processor Nov 21, 2024 Oct 1, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable stack-based buffer overflow vulnerability exists in the JPEG parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted image embedded within a document can cause a length to be miscalculated...Show more |
1Fujielectric 1V Server Firmware Nov 21, 2024 Sep 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote code execution. |
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on buffer length while processing debug log event from firmware can lead to an integer overflow. |
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 28, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An exploitable integer underflow vulnerability exists in the ZigBee firmware update routine of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process incorrectly han...Show more |