CWE-191 · 463 записей
Integer Underflow (Wrap or Wraparound)
CVE этого класса
465 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2014-0497Готовый эксплойт | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Критическая9,8 | KEV | 99,9 % | 5 февр. 2014 г. |
68На этой неделе | CVE-2021-31956Готовый эксплойт | Windows NTFS Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-191 | Высокая7,8 | KEV | 22,3 % | 8 июн. 2021 г. |
60На этой неделе | CVE-2024-38063Proof of concept | Windows TCP/IP Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-191 | Критическая9,8 | — | 70,6 % | 13 авг. 2024 г. |
55В плане | CVE-2020-36221Эксплойта нет | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resultopenldap · openldap · CWE-191 | Высокая7,5 | — | 85,0 % | 26 янв. 2021 г. |
55В плане | CVE-2020-36228Эксплойта нет | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, ropenldap · openldap · CWE-191 | Высокая7,5 | — | 85,0 % | 26 янв. 2021 г. |
50В плане | CVE-2017-14496Proof of concept | Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specicanonical · ubuntu linux · CWE-191 | Высокая7,5 | — | 66,3 % | 2 окт. 2017 г. |
49В плане | CVE-2023-42118Эксплойта нет | Exim libspf2 Integer Underflow Remote Code Execution Vulnerabilityexim · exim · CWE-191 | Высокая8,8 | — | 47,5 % | 2 мая 2024 г. |
48В плане | CVE-2023-31102Эксплойта нет | Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.7-zip · 7-zip · CWE-191 | Высокая7,8 | — | 57,1 % | 3 нояб. 2023 г. |
46В плане | CVE-2007-0063Эксплойта нет | Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.vmware · ace · CWE-191 | Критическая10,0 | — | 20,4 % | 21 сент. 2007 г. |
45В плане | CVE-2005-0199Proof of concept | Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (abarton · ngircd · CWE-191 | Критическая9,8 | — | 18,8 % | 2 мая 2005 г. |
42В плане | CVE-2016-10166Эксплойта нет | Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remlibgd · libgd · CWE-191 | Критическая9,8 | — | 10,7 % | 15 мар. 2017 г. |
41В плане | CVE-2009-3301Эксплойта нет | Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (applicaapache · openoffice · CWE-191 | Критическая9,3 | — | 12,0 % | 16 февр. 2010 г. |
41В плане | CVE-2018-20181Эксплойта нет | rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamlesrdesktop · rdesktop · CWE-191 | Критическая9,8 | — | 8,2 % | 15 мар. 2019 г. |
41В плане | CVE-2018-20180Эксплойта нет | rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddrdesktop · rdesktop · CWE-191 | Критическая9,8 | — | 8,2 % | 15 мар. 2019 г. |
41В плане | CVE-2018-20179Эксплойта нет | rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_prdesktop · rdesktop · CWE-191 | Критическая9,8 | — | 6,8 % | 15 мар. 2019 г. |
41В плане | CVE-2020-15900Эксплойта нет | A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52.artifex · ghostscript · CWE-191 | Критическая9,8 | — | 5,2 % | 28 июл. 2020 г. |
40В плане | CVE-2021-37706Эксплойта нет | Potential integer underflow upon receiving STUN message in PJSIPteluu · pjsip · CWE-191 | Критическая9,8 | — | 4,6 % | 22 дек. 2021 г. |
40В плане | CVE-2018-14353Эксплойта нет | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.mutt · mutt · CWE-191 | Критическая9,8 | — | 3,7 % | 17 июл. 2018 г. |
40В плане | CVE-2018-14817Эксплойта нет | Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote code execution.fujielectric · v-server firmware · CWE-191 | Критическая9,8 | — | 3,6 % | 26 сент. 2018 г. |
40В плане | CVE-2020-28194Эксплойта нет | Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2.accel-ppp · accel-ppp · CWE-191 | Критическая9,8 | — | 3,0 % | 1 февр. 2021 г. |
40В плане | CVE-2016-1925Эксплойта нет | Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or lha for unix project · lha for unix · CWE-191 | Критическая9,8 | — | 3,0 % | 23 янв. 2017 г. |
40В плане | CVE-2017-9214Эксплойта нет | In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused bopenvswitch · openvswitch · CWE-191 | Критическая9,8 | — | 2,9 % | 23 мая 2017 г. |
40В плане | CVE-2019-14192Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-191 | Критическая9,8 | — | 2,8 % | 31 июл. 2019 г. |
40В плане | CVE-2015-0537Эксплойта нет | Integer underflow in the base64-decoding implementation in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3dell · bsafe · CWE-191 | Критическая9,8 | — | 2,6 % | 20 авг. 2015 г. |
40В плане | CVE-2015-2311Эксплойта нет | Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or capnproto · capnproto · CWE-191 | Критическая9,8 | — | 2,5 % | 9 авг. 2017 г. |
- CVE-2014-049799Срочно
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player5 февр. 2014 г.
- CVE-2021-3195668На этой неделе
Windows NTFS Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 22 %microsoft · windows 10 15078 июн. 2021 г.
- CVE-2024-3806360На этой неделе
Windows TCP/IP Remote Code Execution Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 71 %microsoft · windows 10 150713 авг. 2024 г.
- CVE-2020-3622155В плане
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, result
ВысокаяCVSS 7,5Эксплойта нетEPSS 85 %openldap · openldap26 янв. 2021 г.
- CVE-2020-3622855В плане
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, r
ВысокаяCVSS 7,5Эксплойта нетEPSS 85 %openldap · openldap26 янв. 2021 г.
- CVE-2017-1449650В плане
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is speci
ВысокаяCVSS 7,5Proof of conceptEPSS 66 %canonical · ubuntu linux2 окт. 2017 г.
- CVE-2023-4211849В плане
Exim libspf2 Integer Underflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 48 %exim · exim2 мая 2024 г.
- CVE-2023-3110248В плане
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
ВысокаяCVSS 7,8Эксплойта нетEPSS 57 %7-zip · 7-zip3 нояб. 2023 г.
- CVE-2007-006346В плане
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.
КритическаяCVSS 10,0Эксплойта нетEPSS 20 %vmware · ace21 сент. 2007 г.
- CVE-2005-019945В плане
Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (a
КритическаяCVSS 9,8Proof of conceptEPSS 19 %barton · ngircd2 мая 2005 г.
- CVE-2016-1016642В плане
Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows rem
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %libgd · libgd15 мар. 2017 г.
- CVE-2009-330141В плане
Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (applica
КритическаяCVSS 9,3Эксплойта нетEPSS 12 %apache · openoffice16 февр. 2010 г.
- CVE-2018-2018141В плане
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamles
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %rdesktop · rdesktop15 мар. 2019 г.
- CVE-2018-2018041В плане
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsndd
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %rdesktop · rdesktop15 мар. 2019 г.
- CVE-2018-2017941В плане
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_p
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %rdesktop · rdesktop15 мар. 2019 г.
- CVE-2020-1590041В плане
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %artifex · ghostscript28 июл. 2020 г.
- CVE-2021-3770640В плане
Potential integer underflow upon receiving STUN message in PJSIP
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %teluu · pjsip22 дек. 2021 г.
- CVE-2018-1435340В плане
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %mutt · mutt17 июл. 2018 г.
- CVE-2018-1481740В плане
Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %fujielectric · v-server firmware26 сент. 2018 г.
- CVE-2020-2819440В плане
Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %accel-ppp · accel-ppp1 февр. 2021 г.
- CVE-2016-192540В плане
Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %lha for unix project · lha for unix23 янв. 2017 г.
- CVE-2017-921440В плане
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused b
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %openvswitch · openvswitch23 мая 2017 г.
- CVE-2019-1419240В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %denx · u-boot31 июл. 2019 г.
- CVE-2015-053740В плане
Integer underflow in the base64-decoding implementation in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %dell · bsafe20 авг. 2015 г.
- CVE-2015-231140В плане
Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %capnproto · capnproto9 авг. 2017 г.