CWE-191

Integer Underflow (Wrap or Wraparound)

Parent: CWE-682 - Incorrect Calculation

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

460 vulnerabilities with CWE-191
CVE-2020-15158 HIGH
libIEC61850 <1.4.3 - Buffer Overflow
CVSS 7.7
CVE-2020-17395 HIGH
Parallels Desktop 15.1.4 - Privilege Escalation
CVSS 8.2
CVE-2020-24370 MEDIUM
Lua 5.4.0 - Integer Underflow via getlocal/setlocal Debug Interface
CVSS 5.3
CVE-2020-6098 HIGH
freeDiameter 1.3.2 - Denial of Service via Crafted Diameter Request
CVSS 7.5
CVE-2020-15900 CRITICAL
Artifex Ghostscript 9.50 and 9.52 - Memory Corruption via Non-Standard PostScript Operator
CVSS 9.8
CVE-2020-8174 HIGH
node <10.21.0, 12.18.0, 14.4.0 - Memory Corruption
CVSS 8.1
CVE-2020-14699 HIGH
Oracle VM VirtualBox <5.2.44-6.1.12 - Privilege Escalation
CVSS 7.5
CVE-2020-1400 HIGH
Windows Jet Database Engine - Remote Code Execution via Memory Handling
CVSS 7.8
CVE-2020-2031 MEDIUM
PAN-OS 9.1.0-9.1.2 - Authenticated Denial of Service via dnsproxyd Integer Underflow
CVSS 4.9
CVE-2020-11909 MEDIUM
Treck TCP/IP < 6.0.1.66 - Integer Underflow in IPv4 Processing
CVSS 5.3
CVE-2020-11906 MEDIUM
Treck TCP/IP < 6.0.1.66 - Integer Underflow in Ethernet Link Layer
CVSS 6.3
CVE-2020-1239 HIGH
Windows Media Foundation - Memory Corruption
CVSS 8.8
CVE-2020-6096 HIGH
GNU glibc 2.30.9000 - Memory Corruption
CVSS 8.1
CVE-2019-16160 HIGH
MikroTik RouterOS < 6.45.5 - Unauthenticated Denial of Service via SMB Server Integer Underflow
CVSS 7.5
CVE-2019-15791 HIGH
Linux Kernel shiftfs - Integer Underflow in shiftfs_btrfs_ioctl_fd_replace
CVSS 7.1
CVE-2019-9183 HIGH
Contiki-NG < 4.3 and Contiki < 3.0 - Denial of Service via 6LoWPAN Fragment Processing Integer Underflow
CVSS 7.5
CVE-2019-20590 CRITICAL
Android - Integer Underflow in Secure Storage Trustlet
CVSS 9.8
CVE-2019-14085 HIGH
Qualcomm QCN7605/QCS605/SDA845/SDM670/SDM710/SDM845/SDM850/SM8150/SXR1130 Firmware - Integer Underflow in WLAN Function
CVSS 7.8
CVE-2019-14083 CRITICAL
Qualcomm Snapdragon Firmware - Integer Underflow in SDF Frame Service Descriptor Extended Attribute Parsing
CVSS 9.8
CVE-2019-5148 HIGH
Moxa AWK-3131A Firmware 1.13 - Unauthenticated Denial of Service via Integer Underflow
CVSS 7.5
CVE-2019-16535 CRITICAL
ClickHouse < 19.14 - Remote Code Execution or Denial of Service via Native Protocol Decompression
CVSS 9.8
CVE-2019-5144 HIGH
Kakadu Software SDK 7.10.2 - Heap Overflow
CVSS 8.1
CVE-2019-5099 HIGH
LEADTOOLS 20 - Integer Underflow via CMP Image Parsing
CVSS 7.8
CVE-2019-2187 MEDIUM
Android - Out-of-bounds Read in nfc_ncif.cc
CVSS 5.5
CVE-2019-12678 HIGH
Cisco Adaptive Security Appliance and Firepower Threat Defense - Denial of Service via SIP Message Parsing
CVSS 7.5
Details
Vulnerabilities 460