Skip to content
Noroxi

CWE-191 · 463 records

Integer Underflow (Wrap or Wraparound)

CVEs in this class

465 records

  • Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · flash playerFeb 5, 2014

  • CVE-2021-31956
    68This week

    Windows NTFS Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 22%

    microsoft · windows 10 1507Jun 8, 2021

  • CVE-2024-38063
    60This week

    Windows TCP/IP Remote Code Execution Vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 71%

    microsoft · windows 10 1507Aug 13, 2024

  • An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, result

    HighCVSS 7.5No exploitEPSS 85%

    openldap · openldapJan 26, 2021

  • An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, r

    HighCVSS 7.5No exploitEPSS 85%

    openldap · openldapJan 26, 2021

  • Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is speci

    HighCVSS 7.5Proof of conceptEPSS 66%

    canonical · ubuntu linuxOct 2, 2017

  • Exim libspf2 Integer Underflow Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 48%

    exim · eximMay 2, 2024

  • Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.

    HighCVSS 7.8No exploitEPSS 57%

    7-zip · 7-zipNov 3, 2023

  • Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.

    CriticalCVSS 10.0No exploitEPSS 20%

    vmware · aceSep 21, 2007

  • Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (a

    CriticalCVSS 9.8Proof of conceptEPSS 19%

    barton · ngircdMay 2, 2005

  • Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows rem

    CriticalCVSS 9.8No exploitEPSS 11%

    libgd · libgdMar 15, 2017

  • Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (applica

    CriticalCVSS 9.3No exploitEPSS 12%

    apache · openofficeFeb 16, 2010

  • rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamles

    CriticalCVSS 9.8No exploitEPSS 8%

    rdesktop · rdesktopMar 15, 2019

  • rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsndd

    CriticalCVSS 9.8No exploitEPSS 8%

    rdesktop · rdesktopMar 15, 2019

  • rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_p

    CriticalCVSS 9.8No exploitEPSS 7%

    rdesktop · rdesktopMar 15, 2019

  • A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52.

    CriticalCVSS 9.8No exploitEPSS 5%

    artifex · ghostscriptJul 28, 2020

  • Potential integer underflow upon receiving STUN message in PJSIP

    CriticalCVSS 9.8No exploitEPSS 5%

    teluu · pjsipDec 22, 2021

  • An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.

    CriticalCVSS 9.8No exploitEPSS 4%

    mutt · muttJul 17, 2018

  • Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote code execution.

    CriticalCVSS 9.8No exploitEPSS 4%

    fujielectric · v-server firmwareSep 26, 2018

  • Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2.

    CriticalCVSS 9.8No exploitEPSS 3%

    accel-ppp · accel-pppFeb 1, 2021

  • Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or

    CriticalCVSS 9.8No exploitEPSS 3%

    lha for unix project · lha for unixJan 23, 2017

  • In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused b

    CriticalCVSS 9.8No exploitEPSS 3%

    openvswitch · openvswitchMay 23, 2017

  • An issue was discovered in Das U-Boot through 2019.07.

    CriticalCVSS 9.8No exploitEPSS 3%

    denx · u-bootJul 31, 2019

  • Integer underflow in the base64-decoding implementation in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3

    CriticalCVSS 9.8No exploitEPSS 3%

    dell · bsafeAug 20, 2015

  • Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or

    CriticalCVSS 9.8No exploitEPSS 3%

    capnproto · capnprotoAug 9, 2017

All vulnerability classes