CWE-191

Integer Underflow (Wrap or Wraparound)

Parent: CWE-682 - Incorrect Calculation

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

459 vulnerabilities with CWE-191
CVE-2023-22308 HIGH
SoftEther VPN 5.01.9674 and 5.02 - Denial of Service via OvsProcessData Integer Underflow
CVSS 7.5
CVE-2023-36785 HIGH
Microsoft ODBC Driver for SQL Server - RCE
CVSS 7.8
CVE-2023-44378 HIGH
gnark < 0.9.0 - Incorrect Comparison via Field Overflow
CVSS 7.1
CVE-2023-32653 CRITICAL
Accusoft ImageGear 20.1 - Out-of-Bounds Write via DCM Pixel Data Decode
CVSS 9.8
CVE-2023-38162 HIGH
Windows Server 2012, 2016, 2019, 2022 - Denial of Service via DHCP Server Service Integer Underflow
CVSS 7.5
CVE-2023-36796 HIGH
Microsoft Visual Studio - Remote Code Execution
CVSS 7.8
CVE-2023-36794 HIGH
Microsoft Visual Studio - Remote Code Execution
CVSS 7.8
CVE-2023-40181 MEDIUM
FreeRDP < 2.11.0 - Integer Underflow in zgfx_decompress_segment
CVSS 5.3
CVE-2023-39350 MEDIUM
FreeRDP < 2.11.0 - Denial of Service via Integer Underflow
CVSS 5.9
CVE-2023-36909 MEDIUM
Windows 10/11 and Windows Server 2008/2012/2016/2019 - Denial of Service via MSMQ Integer Underflow
CVSS 6.5
CVE-2023-35387 HIGH
Windows Bluetooth A2DP Driver - Elevation of Privilege via Integer Underflow
CVSS 8.8
CVE-2023-38427 CRITICAL
Linux kernel <6.3.8 - Info Disclosure
CVSS 9.8
CVE-2023-33158 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Integer Underflow
CVSS 7.8
CVE-2023-35790 HIGH
libjxl < 0.8.2 - Denial of Service via Integer Underflow in Patch Decoding
CVSS 7.5
CVE-2023-29349 HIGH
Microsoft ODBC & OLE DB Drivers for SQL Server RCE (17.0.1.1-17.10.4.1, 18.0.2-18.6.0006.0)
CVSS 7.8
CVE-2023-32014 CRITICAL
Microsoft Windows Pragmatic General Multicast - Remote Code Execution
CVSS 9.8
CVE-2023-24817 HIGH
RIOT-OS <2023.04 - Memory Corruption
CVSS 7.5
CVE-2023-31137 HIGH
MaraDNS < 3.5.0036 - Denial of Service via DNS Packet Decompression Integer Underflow
CVSS 7.5
CVE-2023-24821 HIGH
RIOT-OS <2022.10 - Denial of Service
CVSS 7.5
CVE-2023-24820 HIGH
RIOT-OS < 2022.10 - Denial of Service via Crafted 6LoWPAN Frame
CVSS 7.5
CVE-2023-21630 HIGH
Multimedia Framework - Buffer Overflow
CVSS 8.4
CVE-2023-26421 HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - RCE
CVSS 7.8
CVE-2023-28293 HIGH
Windows Kernel - Integer Underflow Elevation of Privilege
CVSS 7.8
CVE-2023-28272 HIGH
Windows Kernel - Elevation of Privilege via Integer Underflow
CVSS 7.8
CVE-2023-28250 CRITICAL
Windows PGM - Remote Code Execution via Integer Underflow
CVSS 9.8
Details
Vulnerabilities 459