CWE-191

Integer Underflow (Wrap or Wraparound)

Parent: CWE-682 - Incorrect Calculation

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

501 vulnerabilities with CWE-191
CVE-2023-39350 MEDIUM
FreeRDP < 2.11.0 - Denial of Service via Integer Underflow
CVSS 5.9
CVE-2023-36909 MEDIUM
Windows 10/11 and Windows Server 2008/2012/2016/2019 - Denial of Service via MSMQ Integer Underflow
CVSS 6.5
CVE-2023-35387 HIGH
Windows Bluetooth A2DP Driver - Elevation of Privilege via Integer Underflow
CVSS 8.8
CVE-2023-38427 CRITICAL
Linux kernel <6.3.8 - Info Disclosure
CVSS 9.8
CVE-2023-33158 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Integer Underflow
CVSS 7.8
CVE-2023-35790 HIGH
libjxl < 0.8.2 - Denial of Service via Integer Underflow in Patch Decoding
CVSS 7.5
CVE-2023-29349 HIGH
Microsoft ODBC & OLE DB Drivers for SQL Server RCE (17.0.1.1-17.10.4.1, 18.0.2-18.6.0006.0)
CVSS 7.8
CVE-2023-32014 CRITICAL
Microsoft Windows Pragmatic General Multicast - Remote Code Execution
CVSS 9.8
CVE-2023-24817 HIGH
RIOT-OS <2023.04 - Memory Corruption
CVSS 7.5
CVE-2023-31137 HIGH
MaraDNS < 3.5.0036 - Denial of Service via DNS Packet Decompression Integer Underflow
CVSS 7.5
CVE-2023-24821 HIGH
RIOT-OS <2022.10 - Denial of Service
CVSS 7.5
CVE-2023-24820 HIGH
RIOT-OS < 2022.10 - Denial of Service via Crafted 6LoWPAN Frame
CVSS 7.5
CVE-2023-21630 HIGH
Multimedia Framework - Buffer Overflow
CVSS 8.4
CVE-2023-26421 HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - RCE
CVSS 7.8
CVE-2023-28293 HIGH
Windows Kernel - Integer Underflow Elevation of Privilege
CVSS 7.8
CVE-2023-28272 HIGH
Windows Kernel - Elevation of Privilege via Integer Underflow
CVSS 7.8
CVE-2023-28250 CRITICAL
Windows PGM - Remote Code Execution via Integer Underflow
CVSS 9.8
CVE-2023-28247 HIGH
Windows Server 2012, 2016, 2019, 2022 - Information Disclosure via Network File System Integer Underflow
CVSS 7.5
CVE-2023-24887 HIGH
Microsoft PostScript and PCL6 Class Printer Driver - RCE
CVSS 8.8
CVE-2023-24911 MEDIUM
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
CVSS 4.3
CVE-2023-24864 HIGH
Microsoft PostScript and PCL6 Class Printer Driver - Privilege Esca...
CVSS 8.8
CVE-2023-21708 CRITICAL
Microsoft Windows RPC Runtime - Remote Code Execution
CVSS 9.8
CVE-2023-20635 MEDIUM
Android - Information Disclosure via Integer Overflow in keyinstall
CVSS 4.4
CVE-2023-21815 HIGH
Visual Studio 2017 15.0-15.9.51, 2019 16.0-16.11.23, 2022 17.0 - Remote Code Execution
CVSS 7.8
CVE-2023-21718 HIGH
Microsoft ODBC Driver for SQL Server - RCE
CVSS 7.8
Details
Vulnerabilities 501