VYPR

CWE-191

Integer Underflow (Wrap or Wraparound)

BaseDraft

Description

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

This can happen in signed and unsigned cases.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (529)

page 17 of 27
  • CVE-2025-48021MedFeb 13, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and versions are as follows: Vnet/IP Interface…

  • CVE-2025-30668MedMay 14, 2025
    risk 0.42cvss 6.5epss 0.01

    Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2024-21466MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while parsing sub-IE length during new IE generation.

  • CVE-2024-30011MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.03

    Windows Hyper-V Denial of Service Vulnerability

  • CVE-2023-36909MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2021-25121MedJun 20, 2022
    risk 0.42cvss 6.5epss 0.01

    The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service on the post/page when a user submit such rating

  • CVE-2021-24894MedNov 23, 2021
    risk 0.42cvss 6.5epss 0.01

    The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page

  • CVE-2021-41821MedSep 29, 2021
    risk 0.42cvss 6.5epss 0.01

    Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.

  • CVE-2026-32775HigMar 16, 2026
    risk 0.41cvss 7.4epss 0.00

    libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.

  • CVE-2023-5753MedOct 25, 2023
    risk 0.41cvss 6.3epss 0.01

    Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c

  • CVE-2020-11906MedJun 17, 2020
    risk 0.41cvss 6.3epss 0.02

    The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.

  • CVE-2026-71389MedAug 11, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-48435MedAug 11, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-50593HigJun 5, 2026
    risk 0.40cvss 7.3epss 0.00

    Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.

  • CVE-2026-34672MedMay 12, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading…

  • CVE-2026-34667MedMay 12, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading…

  • CVE-2026-7736HigMay 4, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version…

  • CVE-2025-55096MedOct 17, 2025
    risk 0.40cvss 6.1epss 0.00

    In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_hid_report_descriptor_get()  when parsing a descriptor of an USB HID device.

  • CVE-2026-48029HigJul 22, 2026
    risk 0.39cvss 7.1epss 0.00

    libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.

  • CVE-2026-57918HigJun 26, 2026
    risk 0.39cvss 7.1epss 0.00

    libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.