CWE-191

Integer Underflow (Wrap or Wraparound)

Parent: CWE-682 - Incorrect Calculation

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

502 vulnerabilities with CWE-191
CVE-2026-29008 HIGH
U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()
CVSS 7.5
CVE-2026-55490 MEDIUM
OpenWrt: EAD Integer Underflow → Pre-Auth Denial of Service
CVSS 6.5
CVE-2026-58016 HIGH
Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
CVSS 7.5
CVE-2026-58058 MEDIUM
Nmap - Integer Underflow in IPv6 Extension Header Parsing
CVSS 6.5
CVE-2026-57918 HIGH
Sahlberg Libnfs - Integer Underflow (Wrap or Wraparound)
CVSS 7.1
CVE-2026-6678 MEDIUM
Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info
CVSS 5.3
CVE-2026-57452 MEDIUM
Vim: Out-of-bounds Read with libsodium-encrypted Files
CVSS 5.5
CVE-2026-53178 HIGH
staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction
CVSS 8.1
CVE-2026-53176 CRITICAL
IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
CVSS 9.8
CVE-2026-53150 MEDIUM
thunderbolt: Reject zero-length property entries in validator
CVSS 5.5
CVE-2026-53130 HIGH
fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START
CVSS 7.8
CVE-2026-52919 HIGH
batman-adv: fix tp_meter counter underflow during shutdown
CVSS 7.8
CVE-2026-30803 CRITICAL
RTI Connext Micro Core Libraries - Integer Underflow
CVSS 9.1
CVE-2026-54413 HIGH
Driftregion iso14229 < 0.9.0 - Out-of-bounds Read
CVSS 8.2
CVE-2026-54412 HIGH
Liambindle Mqtt-c < 1.1.6 - Out-of-bounds Read
CVSS 8.2
CVE-2026-47222 MEDIUM
NanaZip: Heap out-of-bounds read in NanaZip AVB property descriptor parser via unsigned integer underflow
CVSS 5.4
CVE-2026-11850 MEDIUM
Krb5: krb5: integer underflow in berval2tl_data() leads to heap out-of-bounds read
CVSS 5.0
CVE-2026-42542 HIGH
TDengine 3.4.0.0-3.4.1.5 - Unauthenticated Remote Denial of Service
CVSS 7.5
CVE-2026-42326 MEDIUM
ImageMagick: Heap Buffer Over-Read in IPTC encoder
CVSS 5.1
CVE-2026-45469 HIGH
Microsoft Excel Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-45463 HIGH
Microsoft Office Remote Code Execution Vulnerability
CVSS 8.4
CVE-2026-42981 HIGH
Microsoft Windows 11 version 23H2 - Windows Performance Monitor Remote Code Execution Vulnerability
CVSS 8.1
CVE-2026-42980 HIGH
Microsoft Windows 10 Version 1607 - NT OS Kernel Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-11789 MEDIUM
389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer underflow crash
CVSS 4.9
CVE-2026-49494 HIGH
Comodo Internet Security Inspect.sys IPv6 Integer Underflow Remote Denial of Service
CVSS 7.5
Details
Vulnerabilities 502