CWE-191
Integer Underflow (Wrap or Wraparound)
Description
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (529)
page 24 of 27| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20180 | Cri | 0.01 | 9.8 | 0.08 | Mar 15, 2019 | rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably even a remote code execution. | ||
| CVE-2018-20179 | Cri | 0.01 | 9.8 | 0.07 | Mar 15, 2019 | rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_process() and results in memory corruption and probably even a remote code execution. | ||
| CVE-2015-5212 | 0.01 | — | 0.09 | Nov 10, 2015 | Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly… | |||
| CVE-2009-3301 | 0.01 | — | 0.12 | Feb 16, 2010 | Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document. | |||
| CVE-2026-13308 | Hig | 0.00 | 8.1 | 0.01 | Jul 29, 2026 | Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to… | ||
| CVE-2026-42495 | Med | 0.00 | 5.5 | 0.00 | Jul 28, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields… | ||
| CVE-2026-45813 | Hig | 0.00 | 8.8 | 0.00 | Jul 24, 2026 | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. This… | ||
| CVE-2026-44251 | Med | 0.00 | 6.5 | 0.00 | Jul 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-remoted process on the… | ||
| CVE-2026-40955 | Low | 0.00 | 3.7 | 0.00 | Jul 15, 2026 | CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client. | ||
| CVE-2026-40954 | Low | 0.00 | 3.7 | 0.00 | Jul 15, 2026 | CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client | ||
| CVE-2026-48298 | Med | 0.00 | 6.2 | 0.00 | Jul 14, 2026 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of… | ||
| CVE-2026-48296 | Med | 0.00 | 6.2 | 0.00 | Jul 14, 2026 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of… | ||
| CVE-2026-55039 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-50498 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | ||
| CVE-2026-50388 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55011 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-54982 | Hig | 0.00 | 8.8 | 0.00 | Jul 14, 2026 | Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-50308 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-50300 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-49790 | Hig | 0.00 | 7.3 | 0.00 | Jul 14, 2026 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
- risk 0.01cvss 9.8epss 0.08
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably even a remote code execution.
- risk 0.01cvss 9.8epss 0.07
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_process() and results in memory corruption and probably even a remote code execution.
- CVE-2015-5212Nov 10, 2015risk 0.01cvss —epss 0.09
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly…
- CVE-2009-3301Feb 16, 2010risk 0.01cvss —epss 0.12
Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.
- risk 0.00cvss 8.1epss 0.01
Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to…
- risk 0.00cvss 5.5epss 0.00
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields…
- risk 0.00cvss 8.8epss 0.00
Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. This…
- risk 0.00cvss 6.5epss 0.00
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-remoted process on the…
- risk 0.00cvss 3.7epss 0.00
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.
- risk 0.00cvss 3.7epss 0.00
CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client
- risk 0.00cvss 6.2epss 0.00
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…
- risk 0.00cvss 6.2epss 0.00
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…
- risk 0.00cvss 7.8epss 0.00
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
- risk 0.00cvss 7.8epss 0.00
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 8.8epss 0.00
Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.00cvss 7.8epss 0.00
Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 5.5epss 0.00
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.00cvss 7.3epss 0.00
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability