VYPR

CWE-191

Integer Underflow (Wrap or Wraparound)

BaseDraft

Description

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

This can happen in signed and unsigned cases.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (529)

page 24 of 27
  • CVE-2018-20180CriMar 15, 2019
    risk 0.01cvss 9.8epss 0.08

    rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably even a remote code execution.

  • CVE-2018-20179CriMar 15, 2019
    risk 0.01cvss 9.8epss 0.07

    rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_process() and results in memory corruption and probably even a remote code execution.

  • CVE-2015-5212Nov 10, 2015
    risk 0.01cvss epss 0.09

    Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly…

  • CVE-2009-3301Feb 16, 2010
    risk 0.01cvss epss 0.12

    Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.

  • CVE-2026-13308HigJul 29, 2026
    risk 0.00cvss 8.1epss 0.01

    Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to…

  • CVE-2026-42495MedJul 28, 2026
    risk 0.00cvss 5.5epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields…

  • CVE-2026-45813HigJul 24, 2026
    risk 0.00cvss 8.8epss 0.00

    Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. This…

  • CVE-2026-44251MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-remoted process on the…

  • CVE-2026-40955LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

  • CVE-2026-40954LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client

  • CVE-2026-48298MedJul 14, 2026
    risk 0.00cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-48296MedJul 14, 2026
    risk 0.00cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-55039HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-50498HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

  • CVE-2026-50388HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.

  • CVE-2026-55011HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.

  • CVE-2026-54982HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2026-50308HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.

  • CVE-2026-50300MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2026-49790HigJul 14, 2026
    risk 0.00cvss 7.3epss 0.00

    Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability