CWE-191— Integer Underflow
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.— MITRE CWE catalog
501 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-191page 5 of 11
- CVE-2023-0469MEDIUMCVSS 5.5EG 5.52023-01-26
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Linux Kernel during call cleanup. This flaw may lead to a denial of service.
- CVE-2023-20635MEDIUMCVSS 4.4EG 4.42023-03-07
In keyinstall, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0…
- CVE-2023-21527HIGHCVSS 7.5EG 7.52023-01-10
Windows iSCSI Service Denial of Service Vulnerability
- CVE-2023-21556HIGHCVSS 8.1EG 8.12023-01-10
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
- CVE-2023-21630HIGHCVSS 8.4EG 8.42023-04-13
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
- CVE-2023-21681HIGHCVSS 8.8EG 8.82023-01-10
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- CVE-2023-21684HIGHCVSS 8.8EG 8.82023-02-14
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-21708CRITICALCVSS 9.8EG 9.82023-03-14
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- CVE-2023-21718HIGHCVSS 7.8EG 7.82023-02-14
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2023-21815HIGHCVSS 7.8EG 8.42023-02-14
Visual Studio Remote Code Execution Vulnerability
- CVE-2023-22308HIGHCVSS 7.5EG 7.52023-10-12
An integer underflow vulnerability exists in the vpnserver OvsProcessData functionality of SoftEther VPN 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigg…
- CVE-2023-24817HIGHCVSS 7.5EG 7.52023-05-30
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2023.04, an attacker can send a crafted frame to the device resulting in an integer un…
- CVE-2023-24820HIGHCVSS 7.5EG 7.52023-04-24
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. An attacker can send a crafted frame to the device resulting in a large out of bounds write beyond …
- CVE-2023-24821HIGHCVSS 7.5EG 7.52023-04-24
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a large o…
- CVE-2023-24864HIGHCVSS 8.8EG 8.82023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Elevation of Privilege Vulnerability
- CVE-2023-24887HIGHCVSS 8.8EG 8.82023-04-11
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-24911MEDIUMCVSS 4.3EG 6.52023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- CVE-2023-26421HIGHCVSS 7.8EG 7.82023-04-12
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Integer Underflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Expl…
- CVE-2023-28247HIGHCVSS 7.5EG 7.52023-04-11
Windows Network File System Information Disclosure Vulnerability
- CVE-2023-28250CRITICALCVSS 9.8EG 9.82023-04-11
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- CVE-2023-28272HIGHCVSS 7.8EG 7.82023-04-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-28293HIGHCVSS 7.8EG 7.82023-04-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-28902LOWCVSS 3.3EG 3.32025-06-28
An integer underflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause denial-of-service of the infotainment system. The vulnerability was originally discovered in Sko…
- CVE-2023-29349HIGHCVSS 7.8EG 7.82023-06-16
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
- CVE-2023-31102HIGHCVSS 7.8EG 8.72023-11-03
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
- CVE-2023-31137HIGHCVSS 7.5EG 7.52023-05-09
MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packet decompression function allows an attacker to cause a Deni…
- CVE-2023-32014CRITICALCVSS 9.8EG 9.82023-06-14
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- CVE-2023-32653CRITICALCVSS 9.8EG 9.82023-09-25
An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to tri…
- CVE-2023-33059HIGHCVSS 7.8EG 7.82023-11-07
Memory corruption in Audio while processing the VOC packet data from ADSP.
- CVE-2023-33158HIGHCVSS 7.8EG 7.82023-07-11
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2023-35387HIGHCVSS 8.8EG 8.82023-08-08
Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability
- CVE-2023-35790HIGHCVSS 7.5EG 7.52023-06-16
An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a denial of service, such as an infinite loop.
- CVE-2023-36785HIGHCVSS 7.8EG 7.82023-10-10
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2023-36794HIGHCVSS 7.8EG 7.82023-09-12
Visual Studio Remote Code Execution Vulnerability
- CVE-2023-36796HIGHCVSS 7.8EG 7.82023-09-12
Visual Studio Remote Code Execution Vulnerability
- CVE-2023-36909MEDIUMCVSS 6.5EG 6.52023-08-08
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- CVE-2023-38162HIGHCVSS 7.5EG 7.52023-09-12
DHCP Server Service Denial of Service Vulnerability
- CVE-2023-38427CRITICALCVSS 9.8EG 9.82023-07-18
An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts.
- CVE-2023-39350MEDIUMCVSS 5.9EG 5.92023-08-31
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. This issue affects Clients only. Integer underflow leading to DOS (e.g. abort due to `WINPR_ASSERT` with default compilation flags). …
- CVE-2023-39413HIGHCVSS 7.0EG 7.02024-01-08
Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to…
- CVE-2023-39414HIGHCVSS 7.0EG 7.02024-01-08
Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to…
- CVE-2023-40181MEDIUMCVSS 5.3EG 5.32023-08-31
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Integer-Underflow leading to Out-Of-Bound Read in the `zgfx_decompress_segment` function. In the …
- CVE-2023-42118HIGHCVSS 8.8EG 8.92024-05-03
Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim libspf2. Authentication is not required to exploit this vu…
- CVE-2023-43628HIGHCVSS 7.5EG 7.52023-12-05
An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacker can send a malicious packet to trigger this vulnerability.
- CVE-2023-44378MEDIUMCVSS 5.5EG 5.52023-10-09
gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit values, it is possible to construct two valid decomposition to bits. In addition to the canonical decomposition of `a`…
- CVE-2023-47360HIGHCVSS 7.5EG 7.52023-11-07
Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.
- CVE-2023-48298HIGHCVSS 7.5EG 7.52023-12-21
ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerability is an integer underflow resulting in crash due to stack buffer overflow in decompress…
- CVE-2023-52705MEDIUMCVSS 5.5EG 5.52024-05-21
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix underflow in second superblock position calculations Macro NILFS_SB2_OFFSET_BYTES, which computes the position of the second superblock, underflows when the …
- CVE-2023-53189MEDIUMCVSS 5.5EG 5.52025-09-15
In the Linux kernel, the following vulnerability has been resolved: ipv6/addrconf: fix a potential refcount underflow for idev Now in addrconf_mod_rs_timer(), reference idev depends on whether rs_timer is not pending. Then modify rs_time…
- CVE-2023-53226MEDIUMCVSS 5.5EG 5.52025-09-15
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix OOB and integer underflow when rx packets Make sure mwifiex_process_mgmt_packet, mwifiex_process_sta_rx_packet and mwifiex_process_uap_rx_packet, mwif…
Map vulnerabilities like CWE-191 to your infrastructure
EchelonGraph correlates every CVE — across CWE-191 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →