VYPR

CWE-191

Integer Underflow (Wrap or Wraparound)

BaseDraft

Description

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

This can happen in signed and unsigned cases.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (529)

page 12 of 27
  • CVE-2024-47545HigDec 12, 2024
    risk 0.49cvss 7.5epss 0.01

    GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in qtdemux_parse_trak function within qtdemux.c. During the strf parsing case, the subtraction size -= 40 can lead to a negative integer overflow if it is less…

  • CVE-2024-30070HigJun 11, 2024
    risk 0.49cvss 7.5epss 0.02

    DHCP Server Service Denial of Service Vulnerability

  • CVE-2023-47360HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.

  • CVE-2023-22308HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    An integer underflow vulnerability exists in the vpnserver OvsProcessData functionality of SoftEther VPN 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-28247HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Network File System Information Disclosure Vulnerability

  • CVE-2023-21527HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows iSCSI Service Denial of Service Vulnerability

  • CVE-2022-20516HigDec 16, 2022
    risk 0.49cvss 7.5epss 0.01

    In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20483HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds reads due to integer overflows. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed…

  • CVE-2022-37301HigNov 22, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon M340 CPU (part numbers BMXP34*)(V3.40 and prior), Modicon…

  • CVE-2022-2335HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.

  • CVE-2021-44509HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause an integer underflow of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c in order to cause a segmentation fault and crash the application.

  • CVE-2021-44489HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause an integer underflow of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c in order to cause a segmentation fault and crash the application. This is a "- digs"…

  • CVE-2021-40054HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is an integer underflow vulnerability in the atcmdserver module. Successful exploitation of this vulnerability may affect integrity.

  • CVE-2021-31889HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0). Malformed TCP packets with a corrupted SACK…

  • CVE-2021-3321HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.01

    Integer Underflow in Zephyr in IEEE 802154 Fragment Reassembly Header Removal. Zephyr versions >= >=2.4.0 contain Integer Overflow to Buffer Overflow (CWE-680). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-w44j-66g7-xw99

  • CVE-2021-22379HigAug 2, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Integer Underflow (Wrap or Wraparound) Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause DoS of Samgr.

  • CVE-2021-33536HigJun 25, 2021
    risk 0.49cvss 7.5epss 0.01

    In Weidmueller Industrial WLAN devices in multiple versions an exploitable denial-of-service vulnerability exists in ServiceAgent functionality. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds…

  • CVE-2021-25849HigMay 10, 2021
    risk 0.49cvss 7.5epss 0.01

    An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, improper validation of the PortID TLV leads to Denial of Service via a crafted lldp packet.

  • CVE-2021-25846HigMay 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a negative number passed to the memcpy function via a crafted lldp packet.

  • CVE-2021-28362HigMar 24, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Contiki through 3.0. When sending an ICMPv6 error message because of invalid extension header options in an incoming IPv6 packet, there is an attempt to remove the RPL extension headers. Because the packet length and the extension header length are…