VYPR

CWE-191

Integer Underflow (Wrap or Wraparound)

BaseDraft

Description

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

This can happen in signed and unsigned cases.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (582)

page 19 of 30
  • CVE-2024-21466MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while parsing sub-IE length during new IE generation.

  • CVE-2024-30011MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.03

    Windows Hyper-V Denial of Service Vulnerability

  • CVE-2023-36909MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2021-25121MedJun 20, 2022
    risk 0.42cvss 6.5epss 0.01

    The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service on the post/page when a user submit such rating

  • CVE-2021-24894MedNov 23, 2021
    risk 0.42cvss 6.5epss 0.01

    The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page

  • CVE-2021-41821MedSep 29, 2021
    risk 0.42cvss 6.5epss 0.01

    Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.

  • CVE-2026-18341MedSep 4, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.

  • CVE-2026-32775HigMar 16, 2026
    risk 0.41cvss 7.4epss 0.00

    libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.

  • CVE-2023-5753MedOct 25, 2023
    risk 0.41cvss 6.3epss 0.01

    Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c

  • CVE-2020-11906MedJun 17, 2020
    risk 0.41cvss 6.3epss 0.02

    The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.

  • CVE-2026-76189MedAug 25, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-71444MedAug 25, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-71389MedAug 11, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-48435MedAug 11, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-48298MedJul 14, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-48296MedJul 14, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-50593HigJun 5, 2026
    risk 0.40cvss 7.3epss 0.00

    Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.

  • CVE-2026-34672MedMay 12, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading…

  • CVE-2026-34667MedMay 12, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading…

  • CVE-2026-7736HigMay 4, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version…