CWE-191

Integer Underflow (Wrap or Wraparound)

Parent: CWE-682 - Incorrect Calculation

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

459 vulnerabilities with CWE-191
CVE-2026-40386 MEDIUM
libexif < 0.6.25 - Integer Underflow in Fuji and Olympus MakerNote Decoding
CVSS 4.0
CVE-2026-5188 HIGH
Integer underflow in X.509 SAN parsing in wolfSSL
CVSS 8.1
CVE-2026-5778 MEDIUM
Integer underflow leads to out-of-bounds access in sniffer ChaCha decrypt path.
CVSS 6.5
CVE-2026-39855 MEDIUM
osslsigncode <2.13 PE Page Hashing - Out-of-Bounds Read
CVSS 5.5
CVE-2026-39314 MEDIUM
CUPS <=2.4.16 _ppdCreateFromIPP - Integer Underflow
CVSS 4.0
CVE-2026-33184 HIGH
nimiq/core-rs-albatross: Discovery handshake limit could underflow and later provoke a deterministic overflow panic
CVSS 7.5
CVE-2026-34165 MEDIUM
go-git: Maliciously crafted idx file can cause asymmetric memory consumption
CVSS 5.0
CVE-2026-25075 HIGH
strongSwan 4.5.0-6.0.4 - Unauthenticated Denial of Service via EAP-TTLS AVP Parser Integer Underflow
CVSS 7.5
CVE-2026-1005 MEDIUM
Integer underflow leads to out-of-bounds access in sniffer AES-GCM/CCM/ARIA-GCM decrypt path
CVSS 5.3
CVE-2026-2369 MEDIUM
Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources
CVSS 6.5
CVE-2026-25772 MEDIUM
Wazuh Database Synchronization Vulnerable to Stack-based Buffer Overflow via snprintf Integer Underflow
CVSS 4.9
CVE-2026-3084 HIGH
GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-32775 HIGH
libexif through 0.6.25 - Memory Corruption
CVSS 7.4
CVE-2026-31883 MEDIUM
FreeRDP <3.24.0 - Heap Buffer Overflow
CVSS 6.5
CVE-2026-29776 LOW
FreeRDP <3.24.0 - Memory Corruption
CVSS 3.1
CVE-2026-29078 HIGH
lexbor < 2.7.0 - Integer Underflow via ISO-2022-JP Encoder
CVSS 7.5
CVE-2026-3538 HIGH
Google Chrome <145.0.7632.159 - Memory Corruption
CVSS 8.8
CVE-2026-27596 HIGH
exiv2 < 0.28.8 - Out-of-bounds Read via Preview Component
CVSS 7.5
CVE-2026-23748 LOW
Golioth Firmware SDK 0.10.0-0.21.9 - Memory Corruption
CVSS 3.7
CVE-2026-27710 MEDIUM
NanaZip 5.0.1252.0-6.0.1637.0 - DoS
CVSS 5.0
CVE-2026-3172 HIGH
pgvector 0.6.0-0.8.1 - Buffer Overflow
CVSS 8.1
CVE-2026-25532 MEDIUM
ESP-IDF 5.1.6-5.5.2 - Integer Underflow via Malformed EAP-WSC Packet
CVSS 6.3
CVE-2026-23069 MEDIUM
Linux Kernel - Integer Underflow in virtio_transport_get_credit()
CVSS 5.5
CVE-2026-23951 MEDIUM
SumatraPDF - Out-of-bounds Read in PalmDbReader Mobi File Handling
CVSS 5.5
CVE-2026-20957 HIGH
Microsoft Office Excel - Code Injection
CVSS 7.8
Details
Vulnerabilities 459