CWE-191
Integer Underflow (Wrap or Wraparound)
Description
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (582)
page 19 of 30| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21466 | Med | 0.42 | 6.5 | 0.00 | Jul 1, 2024 | Information disclosure while parsing sub-IE length during new IE generation. | ||
| CVE-2024-30011 | Med | 0.42 | 6.5 | 0.03 | May 14, 2024 | Windows Hyper-V Denial of Service Vulnerability | ||
| CVE-2023-36909 | Med | 0.42 | 6.5 | 0.02 | Aug 8, 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2021-25121 | Med | 0.42 | 6.5 | 0.01 | Jun 20, 2022 | The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service on the post/page when a user submit such rating | ||
| CVE-2021-24894 | Med | 0.42 | 6.5 | 0.01 | Nov 23, 2021 | The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page | ||
| CVE-2021-41821 | Med | 0.42 | 6.5 | 0.01 | Sep 29, 2021 | Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager. | ||
| CVE-2026-18341 | Med | 0.41 | 6.3 | 0.00 | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow. | ||
| CVE-2026-32775 | Hig | 0.41 | 7.4 | 0.00 | Mar 16, 2026 | libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow. | ||
| CVE-2023-5753 | Med | 0.41 | 6.3 | 0.01 | Oct 25, 2023 | Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c | ||
| CVE-2020-11906 | Med | 0.41 | 6.3 | 0.02 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow. | ||
| CVE-2026-76189 | Med | 0.40 | 6.2 | 0.00 | Aug 25, 2026 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of… | ||
| CVE-2026-71444 | Med | 0.40 | 6.2 | 0.00 | Aug 25, 2026 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of… | ||
| CVE-2026-71389 | Med | 0.40 | 6.2 | 0.00 | Aug 11, 2026 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of… | ||
| CVE-2026-48435 | Med | 0.40 | 6.2 | 0.00 | Aug 11, 2026 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of… | ||
| CVE-2026-48298 | Med | 0.40 | 6.2 | 0.00 | Jul 14, 2026 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of… | ||
| CVE-2026-48296 | Med | 0.40 | 6.2 | 0.00 | Jul 14, 2026 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of… | ||
| CVE-2026-50593 | Hig | 0.40 | 7.3 | 0.00 | Jun 5, 2026 | Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range. | ||
| CVE-2026-34672 | Med | 0.40 | 6.2 | 0.00 | May 12, 2026 | CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading… | ||
| CVE-2026-34667 | Med | 0.40 | 6.2 | 0.00 | May 12, 2026 | CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading… | ||
| CVE-2026-7736 | Hig | 0.40 | 7.3 | 0.00 | May 4, 2026 | A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version… |
- risk 0.42cvss 6.5epss 0.00
Information disclosure while parsing sub-IE length during new IE generation.
- risk 0.42cvss 6.5epss 0.03
Windows Hyper-V Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service on the post/page when a user submit such rating
- risk 0.42cvss 6.5epss 0.01
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page
- risk 0.42cvss 6.5epss 0.01
Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.
- risk 0.41cvss 6.3epss 0.00
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.
- risk 0.41cvss 7.4epss 0.00
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer would be overwritten due to an integer underflow.
- risk 0.41cvss 6.3epss 0.01
Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c
- risk 0.41cvss 6.3epss 0.02
The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.
- risk 0.40cvss 6.2epss 0.00
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…
- risk 0.40cvss 6.2epss 0.00
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…
- risk 0.40cvss 6.2epss 0.00
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…
- risk 0.40cvss 6.2epss 0.00
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…
- risk 0.40cvss 6.2epss 0.00
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…
- risk 0.40cvss 6.2epss 0.00
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…
- risk 0.40cvss 7.3epss 0.00
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
- risk 0.40cvss 6.2epss 0.00
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading…
- risk 0.40cvss 6.2epss 0.00
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading…
- risk 0.40cvss 7.3epss 0.00
A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version…