CWE-191

Integer Underflow (Wrap or Wraparound)

Parent: CWE-682 - Incorrect Calculation

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

501 vulnerabilities with CWE-191
CVE-2021-27486 HIGH
FATEK Automation WinProladder <3.30 - RCE
CVSS 7.8
CVE-2021-28362 HIGH
Contiki < 3.0 - Denial of Service via ICMPv6 Error Message with Invalid Extension Header
CVSS 7.5
CVE-2021-28027 CRITICAL
bam < 0.1.3 - Integer Underflow and Out-of-Bounds Write during BGZIP Block Loading
CVSS 9.8
CVE-2020-24837 HIGH
zcfees - Integer Underflow via Timestamp Manipulation
CVSS 7.5
CVE-2020-28194 CRITICAL
accel-ppp < 1.12.0-e9d369a - Integer Underflow in RADIUS Vendor-Specific Attribute Handling
CVSS 9.8
CVE-2020-36228 HIGH
OpenLDAP < 2.4.57 - Denial of Service via Certificate List Exact Assertion Integer Underflow
CVSS 7.5
CVE-2020-36221 HIGH
OpenLDAP < 2.4.57 - Denial of Service via Certificate Exact Assertion Integer Underflow
CVSS 7.5
CVE-2020-3691 CRITICAL
Qualcomm Snapdragon - Memory Corruption via Integer Underflow in Audio Processing
CVSS 9.8
CVE-2020-16273 HIGH
Armv8-M Firmware - Integer Underflow via Stack Selection Mechanism
CVSS 7.8
CVE-2020-11208 HIGH
Qualcomm Sd820 Firmware - Integer Underflow
CVSS 7.8
CVE-2020-14378 LOW
DPDK 18.02.1-18.11.9 - Integer Underflow in move_desc Function
CVSS 3.3
CVE-2020-14362 HIGH
X.Org Server < 1.20.9 - Integer Underflow to Heap-Buffer Overflow
CVSS 7.8
CVE-2020-14361 HIGH
X.Org Server < 1.20.9 - Integer Underflow to Heap-Buffer Overflow
CVSS 7.8
CVE-2020-14346 HIGH
x.org X Server < 1.20.9 - Integer Underflow in X Input Extension Protocol Decoding
CVSS 7.8
CVE-2020-3634 CRITICAL
Snapdragon Auto Snapdragon Compute Snapdragon Consumer IOT Snapdrag...
CVSS 9.1
CVE-2020-3675 CRITICAL
Snapdragon Auto - Integer Underflow
CVSS 9.8
CVE-2020-15158 HIGH
libIEC61850 <1.4.3 - Buffer Overflow
CVSS 7.7
CVE-2020-17395 HIGH
Parallels Desktop 15.1.4 - Privilege Escalation
CVSS 8.2
CVE-2020-24370 MEDIUM
Lua 5.4.0 - Integer Underflow via getlocal/setlocal Debug Interface
CVSS 5.3
CVE-2020-6098 HIGH
freeDiameter 1.3.2 - Denial of Service via Crafted Diameter Request
CVSS 7.5
CVE-2020-15900 CRITICAL
Artifex Ghostscript 9.50 and 9.52 - Memory Corruption via Non-Standard PostScript Operator
CVSS 9.8
CVE-2020-8174 HIGH
node <10.21.0, 12.18.0, 14.4.0 - Memory Corruption
CVSS 8.1
CVE-2020-14699 HIGH
Oracle VM VirtualBox <5.2.44-6.1.12 - Privilege Escalation
CVSS 7.5
CVE-2020-1400 HIGH
Windows Jet Database Engine - Remote Code Execution via Memory Handling
CVSS 7.8
CVE-2020-2031 MEDIUM
PAN-OS 9.1.0-9.1.2 - Authenticated Denial of Service via dnsproxyd Integer Underflow
CVSS 4.9
Details
Vulnerabilities 501