CWE-191 · 463 records
Integer Underflow (Wrap or Wraparound)
CVEs in this class
465 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2014-0497Weaponized | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Critical9.8 | KEV | 99.9% | Feb 5, 2014 |
68This week | CVE-2021-31956Weaponized | Windows NTFS Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-191 | High7.8 | KEV | 22.3% | Jun 8, 2021 |
60This week | CVE-2024-38063Proof of concept | Windows TCP/IP Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-191 | Critical9.8 | — | 70.6% | Aug 13, 2024 |
55Plan | CVE-2020-36221No exploit | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resultopenldap · openldap · CWE-191 | High7.5 | — | 85.0% | Jan 26, 2021 |
55Plan | CVE-2020-36228No exploit | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, ropenldap · openldap · CWE-191 | High7.5 | — | 85.0% | Jan 26, 2021 |
50Plan | CVE-2017-14496Proof of concept | Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specicanonical · ubuntu linux · CWE-191 | High7.5 | — | 66.3% | Oct 2, 2017 |
49Plan | CVE-2023-42118No exploit | Exim libspf2 Integer Underflow Remote Code Execution Vulnerabilityexim · exim · CWE-191 | High8.8 | — | 47.5% | May 2, 2024 |
48Plan | CVE-2023-31102No exploit | Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.7-zip · 7-zip · CWE-191 | High7.8 | — | 57.1% | Nov 3, 2023 |
46Plan | CVE-2007-0063No exploit | Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.vmware · ace · CWE-191 | Critical10.0 | — | 20.4% | Sep 21, 2007 |
45Plan | CVE-2005-0199Proof of concept | Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (abarton · ngircd · CWE-191 | Critical9.8 | — | 18.8% | May 2, 2005 |
42Plan | CVE-2016-10166No exploit | Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remlibgd · libgd · CWE-191 | Critical9.8 | — | 10.7% | Mar 15, 2017 |
41Plan | CVE-2009-3301No exploit | Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (applicaapache · openoffice · CWE-191 | Critical9.3 | — | 12.0% | Feb 16, 2010 |
41Plan | CVE-2018-20181No exploit | rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamlesrdesktop · rdesktop · CWE-191 | Critical9.8 | — | 8.2% | Mar 15, 2019 |
41Plan | CVE-2018-20180No exploit | rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddrdesktop · rdesktop · CWE-191 | Critical9.8 | — | 8.2% | Mar 15, 2019 |
41Plan | CVE-2018-20179No exploit | rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_prdesktop · rdesktop · CWE-191 | Critical9.8 | — | 6.8% | Mar 15, 2019 |
41Plan | CVE-2020-15900No exploit | A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52.artifex · ghostscript · CWE-191 | Critical9.8 | — | 5.2% | Jul 28, 2020 |
40Plan | CVE-2021-37706No exploit | Potential integer underflow upon receiving STUN message in PJSIPteluu · pjsip · CWE-191 | Critical9.8 | — | 4.6% | Dec 22, 2021 |
40Plan | CVE-2018-14353No exploit | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-191 | Critical9.8 | — | 3.7% | Jul 17, 2018 |
40Plan | CVE-2018-14817No exploit | Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote code execution.fujielectric · v-server firmware · CWE-191 | Critical9.8 | — | 3.6% | Sep 26, 2018 |
40Plan | CVE-2020-28194No exploit | Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2.accel-ppp · accel-ppp · CWE-191 | Critical9.8 | — | 3.0% | Feb 1, 2021 |
40Plan | CVE-2016-1925No exploit | Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or lha for unix project · lha for unix · CWE-191 | Critical9.8 | — | 3.0% | Jan 23, 2017 |
40Plan | CVE-2017-9214No exploit | In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused bopenvswitch · openvswitch · CWE-191 | Critical9.8 | — | 2.9% | May 23, 2017 |
40Plan | CVE-2019-14192No exploit | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-191 | Critical9.8 | — | 2.8% | Jul 31, 2019 |
40Plan | CVE-2015-0537No exploit | Integer underflow in the base64-decoding implementation in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3dell · bsafe · CWE-191 | Critical9.8 | — | 2.6% | Aug 20, 2015 |
40Plan | CVE-2015-2311No exploit | Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or capnproto · capnproto · CWE-191 | Critical9.8 | — | 2.5% | Aug 9, 2017 |
- CVE-2014-049799Now
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · flash playerFeb 5, 2014
- CVE-2021-3195668This week
Windows NTFS Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 22%microsoft · windows 10 1507Jun 8, 2021
- CVE-2024-3806360This week
Windows TCP/IP Remote Code Execution Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 71%microsoft · windows 10 1507Aug 13, 2024
- CVE-2020-3622155Plan
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, result
HighCVSS 7.5No exploitEPSS 85%openldap · openldapJan 26, 2021
- CVE-2020-3622855Plan
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, r
HighCVSS 7.5No exploitEPSS 85%openldap · openldapJan 26, 2021
- CVE-2017-1449650Plan
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is speci
HighCVSS 7.5Proof of conceptEPSS 66%canonical · ubuntu linuxOct 2, 2017
- CVE-2023-4211849Plan
Exim libspf2 Integer Underflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 48%exim · eximMay 2, 2024
- CVE-2023-3110248Plan
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
HighCVSS 7.8No exploitEPSS 57%7-zip · 7-zipNov 3, 2023
- CVE-2007-006346Plan
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.
CriticalCVSS 10.0No exploitEPSS 20%vmware · aceSep 21, 2007
- CVE-2005-019945Plan
Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (a
CriticalCVSS 9.8Proof of conceptEPSS 19%barton · ngircdMay 2, 2005
- CVE-2016-1016642Plan
Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows rem
CriticalCVSS 9.8No exploitEPSS 11%libgd · libgdMar 15, 2017
- CVE-2009-330141Plan
Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (applica
CriticalCVSS 9.3No exploitEPSS 12%apache · openofficeFeb 16, 2010
- CVE-2018-2018141Plan
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamles
CriticalCVSS 9.8No exploitEPSS 8%rdesktop · rdesktopMar 15, 2019
- CVE-2018-2018041Plan
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsndd
CriticalCVSS 9.8No exploitEPSS 8%rdesktop · rdesktopMar 15, 2019
- CVE-2018-2017941Plan
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_p
CriticalCVSS 9.8No exploitEPSS 7%rdesktop · rdesktopMar 15, 2019
- CVE-2020-1590041Plan
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52.
CriticalCVSS 9.8No exploitEPSS 5%artifex · ghostscriptJul 28, 2020
- CVE-2021-3770640Plan
Potential integer underflow upon receiving STUN message in PJSIP
CriticalCVSS 9.8No exploitEPSS 5%teluu · pjsipDec 22, 2021
- CVE-2018-1435340Plan
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
CriticalCVSS 9.8No exploitEPSS 4%mutt · muttJul 17, 2018
- CVE-2018-1481740Plan
Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote code execution.
CriticalCVSS 9.8No exploitEPSS 4%fujielectric · v-server firmwareSep 26, 2018
- CVE-2020-2819440Plan
Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2.
CriticalCVSS 9.8No exploitEPSS 3%accel-ppp · accel-pppFeb 1, 2021
- CVE-2016-192540Plan
Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or
CriticalCVSS 9.8No exploitEPSS 3%lha for unix project · lha for unixJan 23, 2017
- CVE-2017-921440Plan
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused b
CriticalCVSS 9.8No exploitEPSS 3%openvswitch · openvswitchMay 23, 2017
- CVE-2019-1419240Plan
An issue was discovered in Das U-Boot through 2019.07.
CriticalCVSS 9.8No exploitEPSS 3%denx · u-bootJul 31, 2019
- CVE-2015-053740Plan
Integer underflow in the base64-decoding implementation in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3
CriticalCVSS 9.8No exploitEPSS 3%dell · bsafeAug 20, 2015
- CVE-2015-231140Plan
Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or
CriticalCVSS 9.8No exploitEPSS 3%capnproto · capnprotoAug 9, 2017