CWE-191

Integer Underflow (Wrap or Wraparound)

Parent: CWE-682 - Incorrect Calculation

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

501 vulnerabilities with CWE-191
CVE-2020-11909 MEDIUM
Treck TCP/IP < 6.0.1.66 - Integer Underflow in IPv4 Processing
CVSS 5.3
CVE-2020-11906 MEDIUM
Treck TCP/IP < 6.0.1.66 - Integer Underflow in Ethernet Link Layer
CVSS 6.3
CVE-2020-1239 HIGH
Windows Media Foundation - Memory Corruption
CVSS 8.8
CVE-2020-6096 HIGH
GNU glibc 2.30.9000 - Memory Corruption
CVSS 8.1
CVE-2019-16160 HIGH
MikroTik RouterOS < 6.45.5 - Unauthenticated Denial of Service via SMB Server Integer Underflow
CVSS 7.5
CVE-2019-15791 HIGH
Linux Kernel shiftfs - Integer Underflow in shiftfs_btrfs_ioctl_fd_replace
CVSS 7.1
CVE-2019-9183 HIGH
Contiki-NG < 4.3 and Contiki < 3.0 - Denial of Service via 6LoWPAN Fragment Processing Integer Underflow
CVSS 7.5
CVE-2019-20590 CRITICAL
Android - Integer Underflow in Secure Storage Trustlet
CVSS 9.8
CVE-2019-14085 HIGH
Qualcomm QCN7605/QCS605/SDA845/SDM670/SDM710/SDM845/SDM850/SM8150/SXR1130 Firmware - Integer Underflow in WLAN Function
CVSS 7.8
CVE-2019-14083 CRITICAL
Qualcomm Snapdragon Firmware - Integer Underflow in SDF Frame Service Descriptor Extended Attribute Parsing
CVSS 9.8
CVE-2019-5148 HIGH
Moxa AWK-3131A Firmware 1.13 - Unauthenticated Denial of Service via Integer Underflow
CVSS 7.5
CVE-2019-16535 CRITICAL
ClickHouse < 19.14 - Remote Code Execution or Denial of Service via Native Protocol Decompression
CVSS 9.8
CVE-2019-5144 HIGH
Kakadu Software SDK 7.10.2 - Heap Overflow
CVSS 8.1
CVE-2019-5099 HIGH
LEADTOOLS 20 - Integer Underflow via CMP Image Parsing
CVSS 7.8
CVE-2019-2187 MEDIUM
Android - Out-of-bounds Read in nfc_ncif.cc
CVSS 5.5
CVE-2019-12678 HIGH
Cisco Adaptive Security Appliance and Firepower Threat Defense - Denial of Service via SIP Message Parsing
CVSS 7.5
CVE-2019-10054 HIGH
Suricata <4.1.3 - Memory Corruption
CVSS 7.5
CVE-2019-13104 HIGH
Das U-Boot 2016.11-rc1-2019.07-rc4 - Integer Underflow via Crafted ext4 Filesystem
CVSS 7.8
CVE-2019-14523 HIGH
Schism Tracker <20190722 - Info Disclosure
CVSS 7.8
CVE-2019-14199 CRITICAL
Das U-Boot < 2019.07 - Integer Underflow via UDP Packet Handler
CVSS 9.8
CVE-2019-14192 CRITICAL
Das U-Boot < 2019.07 - Integer Underflow via UDP Packet Processing
CVSS 9.8
CVE-2019-5459 HIGH
VLC Media Player < 3.0.7 - Integer Underflow
CVSS 7.1
CVE-2019-2307 CRITICAL
Snapdragon Auto - Integer Underflow
CVSS 9.8
CVE-2019-13602 HIGH
VLC media player < 3.0.7.1 - Integer Underflow in MP4_EIA608_Convert
CVSS 7.8
CVE-2019-1628 MEDIUM
Cisco Integrated Management Controller - Authenticated Denial of Service via Crafted HTTP Request
CVSS 5.5
Details
Vulnerabilities 501