CWE-191
555 CVEs • Abstraction: Base
Integer Underflow (Wrap or Wraparound)
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CVEs (555)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on buffer length while processing debug log event from firmware can lead to an integer overflow. |
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 28, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An exploitable integer underflow vulnerability exists in the ZigBee firmware update routine of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process incorrectly han...Show more |
4Canonical DebianMutt+1 more4Debian Linux MuttNeomutt+1 moreNov 21, 2024 Jul 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow. |
In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp. |
An wrong logical check identified in the transferFrom function of a smart contract implementation for RemiCoin (RMC), an Ethereum ERC20 token, allows the attacker to steal tokens or conduct resultant integer underflow at...Show more |
While processing a debug log event from firmware in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, an integer underflow and...Show more |
The transferFrom function of a smart contract implementation for FuturXE (FXE), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized transfer of digital assets because of a logic error. The developer m...Show more |
In the function csr_update_fils_params_rso(), insufficient validation on a key length can result in an integer underflow leading to a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM,...Show more |
1Qualcomm 35Ipq4019 Firmware Mdm9206 FirmwareMdm9607 Firmware+32 moreNov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM...Show more |
1Qualcomm 18Sd 410 Firmware Sd 412 FirmwareSd 415 Firmware+15 moreNov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808,...Show more |
1Qualcomm 25Mdm9206 Firmware Mdm9650 FirmwareMsm8909w Firmware+22 moreNov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450,...Show more |
2Gnu Redhat4Binutils Enterprise Linux DesktopEnterprise Linux Server+1 moreJun 17, 2026 Feb 28, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (integer underflow or overflow, and application crash) via an E...Show more |
An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-se...Show more |
Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file. |
archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Oct 4, 2017 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c. |
6Canonical DebianGoogle+3 more8Android Debian LinuxDnsmasq+5 moreMay 13, 2026 Oct 3, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS req...Show more |
The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (integer underflow and application crash) or possibly have unspecified other impact via a crafted BPG file, r...Show more |
An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x265 through 2.5, as used in libbpg and other products. A small height value can cause an integer und...Show more |
Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or possibly obtain sensitive information from memory or execute arbitrary code via...Show more |