CWE-191

Integer Underflow (Wrap or Wraparound)

Parent: CWE-682 - Incorrect Calculation

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

502 vulnerabilities with CWE-191
CVE-2026-63362 MEDIUM
o6 Automation open62541 Integer Underflow
CVSS 5.9
CVE-2026-13308 HIGH
Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability
CVSS 8.1
CVE-2026-54345 MEDIUM
gopacket < 1.6.1 - Diameter AVP Integer Underflow Denial of Service
CVE-2026-51254 HIGH
ESP32-audioI2S 3.4.5 - Integer Underflow and Remote Code Execution via MP3 Bitstream Parsing in MP3Decoder::GetBits
CVSS 7.8
CVE-2026-42495 MEDIUM
buffer overruns in libfsimage iso9660 handling
CVSS 5.5
CVE-2026-54890 HIGH
BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
CVE-2026-66033 HIGH
libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation
CVSS 7.5
CVE-2026-45813 HIGH
Apache NimBLE: Incorrect data validation in BASS add/modify source operation
CVSS 8.8
CVE-2026-65704 HIGH
FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder
CVSS 7.8
CVE-2026-48029 HIGH
libheif: heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow
CVSS 7.1
CVE-2026-44251 MEDIUM
Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent message
CVSS 6.5
CVE-2026-40955 LOW
Absolute Secure Access < 14.55 Client Traffic Parser - Client Denial of Service
CVSS 3.7
CVE-2026-40954 LOW
Integer underflow in Secure Access clients prior to 14.55
CVSS 3.7
CVE-2026-48298 MEDIUM
CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
CVSS 6.2
CVE-2026-48296 MEDIUM
CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
CVSS 6.2
CVE-2026-55039 HIGH
Microsoft Excel Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-50498 HIGH
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-50388 HIGH
Microsoft Windows 10 Version 1607 - Windows NTFS Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-55011 HIGH
Microsoft Defender Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-54982 HIGH
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-50308 HIGH
Microsoft Windows 10 Version 1607 - Windows NTFS Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-50300 MEDIUM
Microsoft Windows 10 Version 1607 - Windows DWM Core Library Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-49790 HIGH
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVSS 7.3
CVE-2026-49181 HIGH
Microsoft Windows 10 Version 1607 - Windows DHCP Client Elevation of Privilege Vulnerability
CVSS 7.5
CVE-2026-51540 CRITICAL
OpENer <= 2.3.0 - Memory Corruption via Integer Underflow in SendUnitData Message Processing
CVSS 9.8
Details
Vulnerabilities 502