CWE-191

Integer Underflow (Wrap or Wraparound)

Parent: CWE-682 - Incorrect Calculation

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

459 vulnerabilities with CWE-191
CVE-2025-2258 HIGH
Eclipse ThreadX NetX Duo < 6.4.3 - Denial of Service via Integer Underflow in HTTP Server
CVSS 7.5
CVE-2025-30356 CRITICAL
CryptoLib < 1.4.0 - Heap Buffer Overflow via Incomplete Frame Length Validation
CVSS 9.8
CVE-2025-2581 MEDIUM
xmedcon 0.25.0 - Integer Underflow in DICOM File Handler
CVSS 4.3
CVE-2025-29913 CRITICAL
CryptoLib < 1.4.0 - Heap Buffer Overflow in Crypto_TC_Prep_AAD via Malicious Telecommand Frame
CVSS 9.8
CVE-2025-29912 CRITICAL
CryptoLib < 1.4.0 - Heap Buffer Overflow via Telecommand Packet Frame Length Field
CVSS 9.8
CVE-2025-29909 CRITICAL
NASA CryptoLib < 1.4.0 - Heap Buffer Overflow in Crypto_TC_ApplySecurity
CVSS 9.8
CVE-2025-0728 HIGH
Eclipse ThreadX NetX Duo <6.4.2 - DoS
CVSS 7.5
CVE-2025-0727 HIGH
Eclipse ThreadX NetX Duo <6.4.2 - DoS
CVSS 7.5
CVE-2025-21376 HIGH
Windows LDAP - Remote Code Execution via Race Condition
CVSS 8.1
CVE-2025-21160 HIGH
Adobe Illustrator < 28.7.4 - Integer Underflow leading to Arbitrary Code Execution
CVSS 7.8
CVE-2025-21156 HIGH
InCopy < 19.5.2 - Integer Underflow leading to Arbitrary Code Execution
CVSS 7.8
CVE-2025-21158 HIGH
Adobe InDesign < 19.5.2 - Integer Underflow to Arbitrary Code Execution
CVSS 7.8
CVE-2025-21135 HIGH
Adobe Animate < 23.0.10 - Integer Underflow Leading to Arbitrary Code Execution
CVSS 7.8
CVE-2025-21134 HIGH
Illustrator on iPad < 3.0.8 - Integer Underflow Leading to Arbitrary Code Execution
CVSS 7.8
CVE-2025-21133 HIGH
Illustrator on iPad < 3.0.8 - Integer Underflow Leading to Arbitrary Code Execution
CVSS 7.8
CVE-2025-21122 HIGH
Photoshop 25.0-25.12, 26.0-26.1 - Integer Underflow Leading to Arbitrary Code Execution via Malicious File
CVSS 7.8
CVE-2025-21276 HIGH
Windows 10 1507-24H2 and Windows Server 2008-2012 - Denial of Service via MapUrlToZone Integer Underflow
CVSS 7.5
CVE-2024-54028 HIGH
catdoc 0.95 - Heap-Based Memory Corruption
CVSS 8.4
CVE-2024-50597 MEDIUM
STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0 - Denial of Service via HTTP Server PUT Request Integer Underflow
CVSS 4.3
CVE-2024-50596 MEDIUM
STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0 - Denial of Service via HTTP Server PUT Request Integer Underflow
CVSS 4.3
CVE-2024-50595 MEDIUM
STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0 - Denial of Service via HTTP Server PUT Request Integer Underflow
CVSS 4.3
CVE-2024-50594 MEDIUM
STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0 - Denial of Service via HTTP Server PUT Request Integer Underflow
CVSS 4.3
CVE-2024-10838 CRITICAL
Eclipse Cyclone Data Distribution Service < 0.10.5 - Unauthenticated Integer Underflow via Deserialization
CVSS 9.1
CVE-2024-57843 MEDIUM
Linux Kernel < 6.6.66, 6.6.0-6.6.66, 6.7.0-6.12.5, 6.12.5-6.12.*, 6.13 - Integer Underflow in virtnet_rq_alloc
CVSS 5.5
CVE-2024-57823 CRITICAL
raptor_rdf_syntax_library <= 2.0.16 - Integer Underflow in URI Normalization
CVSS 9.3
Details
Vulnerabilities 459