VYPR

CWE-191

Integer Underflow (Wrap or Wraparound)

BaseDraft

Description

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

This can happen in signed and unsigned cases.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (529)

page 10 of 27
  • CVE-2023-28272HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-21815HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Visual Studio Remote Code Execution Vulnerability

  • CVE-2023-21718HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2022-27492HigSep 23, 2022
    risk 0.51cvss 7.8epss 0.01

    An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file.

  • CVE-2021-27486HigApr 12, 2021
    risk 0.51cvss 7.8epss 0.01

    FATEK Automation WinProladder Versions 3.30 and prior is vulnerable to an integer underflow, which may cause an out-of-bounds write and allow an attacker to execute arbitrary code.

  • CVE-2020-16273HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by a stack-underflow attack in v8-M TrustZone based processors. An attacker can cause a change to the stack pointer used by the Secure World from a non-secure…

  • CVE-2020-11208HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.02

    Out of Bound issue in DSP services while processing received arguments due to improper validation of length received as an argument' in SD820, SD821, SD820, QCS603, QCS605, SDA855, SA6155P, SA6145P, SA6155, SA6155P, SD855, SD 675, SD660, SD429, SD439

  • CVE-2020-14362HigSep 15, 2020
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system…

  • CVE-2020-14361HigSep 15, 2020
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system…

  • CVE-2020-14346HigSep 15, 2020
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as…

  • CVE-2019-14085HigMar 5, 2020
    risk 0.51cvss 7.8epss 0.00

    Possible Integer underflow in WLAN function due to lack of check of data received from user side in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCN7605, QCS605,…

  • CVE-2019-5099HigNov 6, 2019
    risk 0.51cvss 7.8epss 0.02

    An exploitable integer underflow vulnerability exists in the CMP-parsing functionality of LEADTOOLS 20. A specially crafted CMP image file can cause an integer underflow, potentially resulting in code execution. An attacker can specially craft a CMP image to trigger this…

  • CVE-2019-13104HigAug 6, 2019
    risk 0.51cvss 7.8epss 0.01

    In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.

  • CVE-2019-14523HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Schism Tracker through 20190722. There is an integer underflow via a large plen in fmt_okt_load_song in the Amiga Oktalyzer parser in fmt/okt.c.

  • CVE-2019-13602HigJul 14, 2019
    risk 0.51cvss 7.8epss 0.02

    An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.

  • CVE-2017-18278HigMay 6, 2019
    risk 0.51cvss 7.8epss 0.00

    An integer underflow may occur due to lack of check when received data length from font_mgr_qsee_request_service is bigger than the minimal value of the segment header, which may result in a buffer overflow, in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in…

  • CVE-2018-15418HigOct 5, 2018
    risk 0.51cvss 7.8epss 0.02

    A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates…

  • CVE-2018-3999HigOct 1, 2018
    risk 0.51cvss 7.8epss 0.01

    An exploitable stack-based buffer overflow vulnerability exists in the JPEG parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted image embedded within a document can cause a length to be miscalculated and underflow. This length is then treated as unsigned and…

  • CVE-2018-11301HigSep 18, 2018
    risk 0.51cvss 7.8epss 0.00

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on buffer length while processing debug log event from firmware can lead to an integer overflow.

  • CVE-2018-5850HigJun 6, 2018
    risk 0.51cvss 7.8epss 0.00

    In the function csr_update_fils_params_rso(), insufficient validation on a key length can result in an integer underflow leading to a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.