CWE-191

Integer Underflow (Wrap or Wraparound)

Parent: CWE-682 - Incorrect Calculation

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

428 vulnerabilities with CWE-191
CVE-2026-33845 HIGH
Gnutls: gnutls: denial of service via dtls zero-length fragment
CVSS 7.5
CVE-2026-7424 HIGH
Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP
CVSS 8.1
CVE-2026-7423 MEDIUM
Integer Underflow in ICMP Echo Reply Processing in FreeRTOS-Plus-TCP
CVSS 5.3
CVE-2026-41499 MEDIUM
Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()
CVSS 6.5
CVE-2026-26204 MEDIUM
Wazuh: Heap-based NULL WRITE Buffer Underflow in GetAlertData
CVSS 4.4
CVE-2026-6914 MEDIUM
MD5 checksum creation may cause availability loss
CVSS 6.5
CVE-2026-40356 MEDIUM
MIT Kerberos 5 < 1.22.3 - Out-of-Bounds Access
CVSS 5.9
CVE-2026-31662 HIGH
tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG
CVSS 7.5
CVE-2026-31656 HIGH
drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat
CVSS 7.8
CVE-2026-31551 MEDIUM
wifi: mac80211: Fix static_branch_dec() underflow for aql_disable.
CVSS 5.5
CVE-2026-28525 MEDIUM
SWUpdate Integer Underflow in Multipart Upload Parser
CVSS 6.8
CVE-2026-33999 HIGH
Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling
CVSS 7.8
CVE-2026-34064 MEDIUM
nimiq-account: Vesting insufficient funds error can panic
CVSS 5.3
CVE-2026-5720 HIGH
miniupnpd Integer Underflow SOAPAction Header Parsing
CVE-2026-27297 HIGH
Adobe Framemaker | Integer Underflow (Wrap or Wraparound) (CWE-191)
CVSS 7.8
CVE-2026-27296 HIGH
Adobe Framemaker | Integer Underflow (Wrap or Wraparound) (CWE-191)
CVSS 7.8
CVE-2026-32149 HIGH
Windows Hyper-V Remote Code Execution Vulnerability
CVSS 7.3
CVE-2026-27907 HIGH
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-33899 MEDIUM
ImageMagick: Heap BufferOverflow write of single zero byte when parsing XML
CVSS 5.3
CVE-2026-40386 MEDIUM
libexif <0.6.25 - Info Disclosure
CVSS 4.0
CVE-2026-5188 HIGH
Integer underflow in X.509 SAN parsing in wolfSSL
CVSS 8.1
CVE-2026-5778 MEDIUM
Integer underflow leads to out-of-bounds access in sniffer ChaCha decrypt path.
CVSS 6.5
CVE-2026-39855 MEDIUM
osslsigncode has an Integer Underflow in PE Page Hash Calculation Can Cause Out-of-Bounds Read
CVSS 5.5
CVE-2026-39314 MEDIUM
CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported`
CVSS 4.0
CVE-2026-33184 HIGH
nimiq/core-rs-albatross: Discovery handshake limit could underflow and later provoke a deterministic overflow panic
CVSS 7.5
Details
Vulnerabilities 428