CWE-191

Integer Underflow (Wrap or Wraparound)

Parent: CWE-682 - Incorrect Calculation

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

460 vulnerabilities with CWE-191
CVE-2017-3034 HIGH
Adobe Acrobat and Reader < 11.0.19, < 15.006.30280, < 15.023.20070 - Remote Code Execution
CVSS 7.8
CVE-2017-6313 HIGH
gdk-pixbuf < 2.36.12 - Integer Underflow in ICO Image Entry Size Handling
CVSS 7.1
CVE-2016-10268 HIGH
libtiff - Integer Underflow and Heap-Based Buffer Under-Read via Crafted TIFF Image
CVSS 7.8
CVE-2016-10166 CRITICAL
libgd < 2.2.4 - Integer Underflow in _gdContributionsAlloc
CVSS 9.8
CVE-2016-7800 HIGH
GraphicsMagick < 1.3.25 - Denial of Service via Crafted 8BIM Chunk
CVSS 7.5
CVE-2016-1925 CRITICAL
lha_for_unix - Integer Underflow and Buffer Overflow via Large Header Size Value
CVSS 9.8
CVE-2016-2316 MEDIUM
Fedora - Integer Underflow
CVSS 5.9
CVE-2015-9198 CRITICAL
Qualcomm MDM9206 and Snapdragon Firmware - Integer Underflow in qsee_register_log_buff
CVSS 9.8
CVE-2015-9167 CRITICAL
Qualcomm Snapdragon Mobile and Automobile Firmware - Integer Underflow in EMM Command
CVSS 9.8
CVE-2015-9129 CRITICAL
Qualcomm Multiple Chipsets Firmware - Integer Underflow via TZ_PR_CMD_CONTENT_SET_PROP
CVSS 9.8
CVE-2015-1208 MEDIUM
FFmpeg < 2.4.6 - Integer Underflow in mov_read_default Function
CVSS 5.5
CVE-2015-2311 CRITICAL
capnproto < 0.4.1.1 and 0.5.x < 0.5.1.1 - Integer Underflow via Crafted Message
CVSS 9.8
CVE-2015-8370 HIGH
Grub2 1.98-2.02 - Integer Underflow via Backspace Characters in Authentication Functions
CVSS 7.4
CVE-2015-5212
LibreOffice <4.4.5 & Apache OpenOffice <4.1.2 - Memory Corruption
CVE-2015-0537 CRITICAL
Dell Bsafe < 4.0.8 - Integer Underflow
CVSS 9.8
CVE-2014-9626 HIGH
VLC media player < 2.1.6 - Integer Underflow in MP4_ReadBox_String
CVSS 7.8
CVE-2014-9883 HIGH
Android <2016-08-05 - Privilege Escalation
CVSS 7.8
CVE-2014-9087
Libksba <1.3.2 - DoS
CVE-2014-8768
tcpdump <4.7 - DoS
CVE-2014-0497 CRITICAL KEV
Adobe Flash Player Integer Underflow Remote Code Execution
CVSS 9.8
CVE-2013-6425
pixman < 0.32.0 - Integer Underflow via Negative Bottom Value
CVE-2013-6424
pixman < 0.31.2 - Denial of Service via Negative Bottom Value in xTrapezoidValid Macro
CVE-2011-4031
FFmpeg < 0.8.3 - Remote Code Execution via ASF Packet Integer Underflow
CVE-2011-2497
Linux Kernel < 3.0 - Integer Underflow in L2CAP Configuration Request Handling
CVE-2011-1770 HIGH
Linux Kernel < 2.6.33.14 - Denial of Service via DCCP Feature Options Length Integer Underflow
CVSS 7.5
Details
Vulnerabilities 460