The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
502 vulnerabilities with CWE-191
CVE-2026-25075
HIGH
strongSwan 4.5.0-6.0.4 - Unauthenticated Denial of Service via EAP-TTLS AVP Parser Integer Underflow
CVSS 7.5
CVE-2026-1005
MEDIUM
Integer underflow leads to out-of-bounds access in sniffer AES-GCM/CCM/ARIA-GCM decrypt path
CVSS 5.3
CVE-2026-2369
MEDIUM
Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources
CVSS 6.5
CVE-2026-25772
MEDIUM
Wazuh Database Synchronization Vulnerable to Stack-based Buffer Overflow via snprintf Integer Underflow
CVSS 4.9
CVE-2026-3084
HIGH
GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-32775
HIGH
libexif through 0.6.25 - Memory Corruption
CVSS 7.4
CVE-2026-31883
MEDIUM
FreeRDP <3.24.0 - Heap Buffer Overflow
CVSS 6.5
CVE-2026-29776
LOW
FreeRDP <3.24.0 - Memory Corruption
CVSS 3.1
CVE-2026-29078
HIGH
lexbor < 2.7.0 - Integer Underflow via ISO-2022-JP Encoder
CVSS 7.5
CVE-2026-3538
HIGH
Google Chrome <145.0.7632.159 - Memory Corruption
CVSS 8.8
CVE-2026-27596
HIGH
exiv2 < 0.28.8 - Out-of-bounds Read via Preview Component
CVSS 7.5
CVE-2026-23748
LOW
Golioth Firmware SDK 0.10.0-0.21.9 - Memory Corruption
CVSS 3.7
CVE-2026-27710
MEDIUM
NanaZip 5.0.1252.0-6.0.1637.0 - DoS
CVSS 5.0
CVE-2026-3172
HIGH
pgvector 0.6.0-0.8.1 - Buffer Overflow
CVSS 8.1
CVE-2026-25532
MEDIUM
ESP-IDF 5.1.6-5.5.2 - Integer Underflow via Malformed EAP-WSC Packet
CVSS 6.3
CVE-2026-23069
MEDIUM
Linux Kernel - Integer Underflow in virtio_transport_get_credit()
CVSS 5.5
CVE-2026-23951
MEDIUM
SumatraPDF - Out-of-bounds Read in PalmDbReader Mobi File Handling
CVSS 5.5
CVE-2026-20957
HIGH
Microsoft Office Excel - Code Injection
CVSS 7.8
CVE-2026-22185
MEDIUM
OpenLDAP LMDB <0.9.14 - Buffer Overflow
CVE-2026-21489
MEDIUM
iccDEV < 2.3.1.2 - Out-of-bounds Read and Integer Underflow in CIccCalculatorFunc::SequenceNeedTempReset
CVSS 6.1
CVE-2025-14547
LOW
Simplicity SDK < 2025.6.2 and Gecko SDK < 2.5.x - Denial of Service via EC-JPAKE ZKP Parsing Integer Underflow
CVE-2025-14055
LOW
Silicon Labs Secure NCP - Buffer Overflow
CVE-2025-48021
MEDIUM
Yokogawa Electric Corporation - DoS
CVSS 6.5
CVE-2025-1924
HIGH
Yokogawa Electric Corporation - DoS
CVSS 8.2
CVE-2025-62291
HIGH
strongSwan <6.0.3 - Buffer Overflow
CVSS 8.1
Details
Vulnerabilities
502