VYPR

CWE-191

Integer Underflow (Wrap or Wraparound)

BaseDraft

Description

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

This can happen in signed and unsigned cases.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (582)

page 27 of 30
  • CVE-2026-13308HigJul 29, 2026
    risk 0.00cvss 8.1epss 0.01

    Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to…

  • CVE-2026-42495MedJul 28, 2026
    risk 0.00cvss 5.5epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from attacker-controlled on-disk fields…

  • CVE-2026-45813HigJul 24, 2026
    risk 0.00cvss 8.8epss 0.00

    Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. This…

  • CVE-2026-44251MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-remoted process on the…

  • CVE-2026-40955LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

  • CVE-2026-40954LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client

  • CVE-2026-55039HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-50498HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

  • CVE-2026-50388HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.

  • CVE-2026-55011HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.

  • CVE-2026-54982HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2026-50308HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.

  • CVE-2026-50300MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2026-49790HigJul 14, 2026
    risk 0.00cvss 7.3epss 0.00

    Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

  • CVE-2026-49181HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-55490MedJul 7, 2026
    risk 0.00cvss 6.5epss 0.01

    OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted UDP packet. The…

  • CVE-2026-27596HigMar 2, 2026
    risk 0.00cvss 7.5epss 0.00

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running…

  • CVE-2026-25532MedFeb 4, 2026
    risk 0.00cvss 6.3epss 0.00

    ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a vulnerability exists in the WPS (Wi-Fi Protected Setup) Enrollee implementation where malformed EAP-WSC packets with truncated payloads can cause integer…

  • CVE-2026-21489MedJan 6, 2026
    risk 0.00cvss 6.1epss 0.00

    iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have Out-of-bounds Read and Integer Underflow (Wrap or Wraparound) vulnerabilities in its CIccCalculatorFunc::SequenceNeedTempReset function. This issue is…

  • CVE-2025-66217HigNov 29, 2025
    risk 0.00cvss 7.5epss 0.01

    AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQTT parsing logic of AIS-catcher. This vulnerability allows an attacker to trigger a massive Heap Buffer Overflow by sending a malformed MQTT packet with a…