The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
502 vulnerabilities with CWE-191
CVE-2025-47136
HIGH
Adobe InDesign < 19.5.4 - Integer Underflow to Arbitrary Code Execution
CVSS 7.8
CVE-2025-49744
HIGH
Windows 10/11, Server 2016-2019 Local Privilege Escalation via Heap Overflow
CVSS 7.0
CVE-2025-47996
HIGH
Windows 10/11, Server 2008 - Privilege Escalation via MBT Transport Driver Integer Underflow
CVSS 7.8
CVE-2025-38200
MEDIUM
Linux Kernel - Integer Underflow in i40e_clear_hw MMIO Write Access
CVSS 5.5
CVE-2025-38161
HIGH
Linux Kernel - Integer Underflow in RDMA/mlx5 RQ Destruction
CVSS 7.8
CVE-2025-1991
HIGH
IBM Informix Dynamic Server <15.0 - DoS
CVSS 7.5
CVE-2025-52471
CRITICAL
ESP-IDF 5.4.1 5.3.3 5.2.5 5.1.6 - Integer Underflow in ESP-NOW Packet Receive Function
CVSS 9.8
CVE-2025-49112
LOW
Valkey < 8.1.1 - Integer Underflow in setDeferredReply
CVSS 3.1
CVE-2025-4948
HIGH
libsoup - Memory Corruption
CVSS 7.5
CVE-2025-30668
MEDIUM
Zoom Workplace Apps < 6.4.0 - Authenticated Denial of Service via Integer Underflow
CVSS 6.5
CVE-2025-43555
HIGH
Adobe Animate < 23.0.12 - Integer Underflow Leading to Arbitrary Code Execution
CVSS 7.8
CVE-2025-43546
HIGH
Adobe Bridge < 14.1.7 - Integer Underflow leading to Arbitrary Code Execution
CVSS 7.8
CVE-2025-30324
HIGH
Photoshop Desktop <26.5, 25.12.2 - Code Injection
CVSS 7.8
CVE-2025-29974
MEDIUM
Windows 10 1507-22H2 and Windows 11 22H2 - Unauthenticated Information Disclosure via Integer Underflow
CVSS 5.7
CVE-2025-47256
MEDIUM
Libxmp < 4.6.2 - Stack-Based Buffer Overflow via Malformed Pha Format Tracker Module
CVSS 5.6
CVE-2025-26269
LOW
DragonflyDB Dragonfly < 1.29.0 - Authenticated Denial of Service via Lua Library Integer Underflow
CVSS 3.3
CVE-2025-30296
HIGH
Adobe Framemaker <2020.8, 2022.6 - RCE
CVSS 7.8
CVE-2025-2259
HIGH
Eclipse ThreadX NetX Duo < 6.4.3 - Denial of Service via Integer Underflow in HTTP Server
CVSS 7.5
CVE-2025-2258
HIGH
Eclipse ThreadX NetX Duo < 6.4.3 - Denial of Service via Integer Underflow in HTTP Server
CVSS 7.5
CVE-2025-30356
CRITICAL
CryptoLib < 1.4.0 - Heap Buffer Overflow via Incomplete Frame Length Validation
CVSS 9.8
CVE-2025-2581
MEDIUM
xmedcon 0.25.0 - Integer Underflow in DICOM File Handler
CVSS 4.3
CVE-2025-29913
CRITICAL
CryptoLib < 1.4.0 - Heap Buffer Overflow in Crypto_TC_Prep_AAD via Malicious Telecommand Frame
CVSS 9.8
CVE-2025-29912
CRITICAL
CryptoLib < 1.4.0 - Heap Buffer Overflow via Telecommand Packet Frame Length Field
CVSS 9.8
CVE-2025-29909
CRITICAL
NASA CryptoLib < 1.4.0 - Heap Buffer Overflow in Crypto_TC_ApplySecurity
CVSS 9.8
CVE-2025-0728
HIGH
Eclipse ThreadX NetX Duo <6.4.2 - DoS
CVSS 7.5
Details
Vulnerabilities
502