VYPR

CWE-191

Integer Underflow (Wrap or Wraparound)

BaseDraft

Description

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

This can happen in signed and unsigned cases.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (529)

page 5 of 27
  • CVE-2026-59090HigAug 10, 2026
    risk 0.55cvss 8.4epss 0.00

    A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary…

  • CVE-2026-45463HigJun 9, 2026
    risk 0.55cvss 8.4epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2024-54028HigJun 2, 2025
    risk 0.55cvss 8.4epss 0.00

    An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2018-5852HigNov 26, 2024
    risk 0.55cvss 8.4epss 0.00

    An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'

  • CVE-2024-35980HigMay 20, 2024
    risk 0.55cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: arm64: tlb: Fix TLBI RANGE operand KVM/arm64 relies on TLBI RANGE feature to flush TLBs when the dirty pages are collected by VMM and the page table entries become write protected during live migration.…

  • CVE-2023-21630HigApr 13, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.

  • CVE-2023-53679HigOct 7, 2025
    risk 0.54cvss 8.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: wifi: mt7601u: fix an integer underflow Fix an integer underflow that leads to a null pointer dereference in 'mt7601u_rx_skb_from_seg()'. The variable 'dma_len' in the URB packet could be manipulated, which…

  • CVE-2023-42118HigMay 3, 2024
    risk 0.54cvss 8.8epss 0.52

    Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim libspf2. Authentication is not required to exploit this vulnerability. The specific flaw exists…

  • CVE-2023-28293HigApr 11, 2023
    risk 0.54cvss 7.8epss 0.03

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2021-3323HigOct 12, 2021
    risk 0.54cvss 8.3epss 0.01

    Integer Underflow in 6LoWPAN IPHC Header Uncompression in Zephyr. Zephyr versions >= >=2.4.0 contain Integer Underflow (Wrap or Wraparound) (CWE-191). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-89j6-qpxf-pfpc

  • CVE-2026-54413HigJun 14, 2026
    risk 0.53cvss 8.2epss 0.00

    driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially read memory past the receive buffer by…

  • CVE-2026-54412HigJun 14, 2026
    risk 0.53cvss 8.2epss 0.00

    LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an…

  • CVE-2026-42981HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.01

    Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.

  • CVE-2026-3172HigFeb 25, 2026
    risk 0.53cvss 8.1epss 0.00

    Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server.

  • CVE-2025-1924HigFeb 13, 2026
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receive maliciously crafted packets, a DoS attack may cause Vnet/IP communication functions to stop or arbitrary programs to be executed. The affected…

  • CVE-2025-62291HigJan 16, 2026
    risk 0.53cvss 8.1epss 0.01

    In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.

  • CVE-2025-3947HigJul 10, 2025
    risk 0.53cvss 8.2epss 0.00

    The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to Input Data Manipulation, which could result in improper integer data value checking…

  • CVE-2025-21376HigFeb 11, 2025
    risk 0.53cvss 8.1epss 0.09

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2022-28733HigJul 20, 2023
    risk 0.53cvss 8.1epss 0.01

    Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number…

  • CVE-2023-21556HigJan 10, 2023
    risk 0.53cvss 8.1epss 0.01

    Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability