VYPR

CWE-191

Integer Underflow (Wrap or Wraparound)

BaseDraft

Description

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

This can happen in signed and unsigned cases.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (529)

page 4 of 27
  • CVE-2024-11950HigDec 12, 2024
    risk 0.57cvss 8.8epss 0.00

    XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of XnSoft XnView Classic. User interaction is required to exploit this vulnerability in…

  • CVE-2024-28945HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-28933HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-28930HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-26244HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2023-35387HigAug 8, 2023
    risk 0.57cvss 8.8epss 0.01

    Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability

  • CVE-2023-24887HigApr 11, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

  • CVE-2023-24864HigMar 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Elevation of Privilege Vulnerability

  • CVE-2023-21684HigFeb 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

  • CVE-2023-21681HigJan 10, 2023
    risk 0.57cvss 8.8epss 0.01

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2021-4066HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-43083HigDec 19, 2021
    risk 0.57cvss 8.8epss 0.02

    Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to…

  • CVE-2021-21897HigSep 8, 2021
    risk 0.57cvss 8.8epss 0.03

    A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2017-18170HigOct 23, 2018
    risk 0.57cvss 8.8epss 0.01

    Improper input validation in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, SD…

  • CVE-2018-14353CriJul 17, 2018
    risk 0.57cvss 9.8epss 0.04

    An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow.

  • CVE-2017-14496HigOct 3, 2017
    risk 0.57cvss 7.5epss 0.66

    Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.

  • CVE-2017-14796HigSep 28, 2017
    risk 0.57cvss 8.8epss 0.02

    The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (integer underflow and application crash) or possibly have unspecified other impact via a crafted BPG file, related to improper interaction with copy_CTB_to_hv in…

  • CVE-2015-2311CriAug 9, 2017
    risk 0.57cvss 9.8epss 0.03

    Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or possibly obtain sensitive information from memory or execute arbitrary code via a crafted message.

  • CVE-2023-31102HigNov 3, 2023
    risk 0.56cvss 7.8epss 0.71

    Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.

  • CVE-2022-39293HigOct 13, 2022
    risk 0.56cvss 8.6epss 0.01

    Azure RTOS USBX is a high-performance USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. The case is, in [_ux_host_class_pima_read](https://github.com/azure-rtos/usbx/blob/master/common/usbx_host_classes/src/ux_host_class_pima_…