CWE-191

Integer Underflow (Wrap or Wraparound)

Parent: CWE-682 - Incorrect Calculation

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

459 vulnerabilities with CWE-191
CVE-2024-46759 HIGH
Linux Kernel Integer Underflow via DIV_ROUND_CLOSEST
CVSS 7.8
CVE-2024-46730 MEDIUM
Linux Kernel < 6.10.9 - Integer Underflow in DRM AMD Display Timing Generator Index
CVSS 5.5
CVE-2024-6258 MEDIUM
Zephyr < 3.6.0 - Integer Underflow in RFCOMM Data Handling
CVSS 6.8
CVE-2024-41857 HIGH
Illustrator < 27.9.6 - Integer Underflow Leading to Arbitrary Code Execution
CVSS 7.8
CVE-2024-43867 MEDIUM
Linux Kernel - Integer Underflow in Nouveau DRM Prime BO Reference Counting
CVSS 5.5
CVE-2024-38063 CRITICAL
Windows TCP/IP - Remote Code Execution
CVSS 9.8
CVE-2024-38517 HIGH
Tencent RapidJSON - Privilege Escalation
CVSS 7.8
CVE-2024-38074 CRITICAL
Windows Remote Desktop Licensing Service - Remote Code Execution
CVSS 9.8
CVE-2024-38050 HIGH
Windows Workstation Service - Privilege Escalation
CVSS 7.8
CVE-2024-37986 HIGH
Windows Secure Boot - Security Feature Bypass via Integer Underflow
CVSS 8.0
CVE-2024-37981 HIGH
Windows Secure Boot Security Feature Bypass via Integer Underflow
CVSS 8.0
CVE-2024-37975 HIGH
Windows Secure Boot - Security Feature Bypass via Integer Underflow
CVSS 8.0
CVE-2024-37974 HIGH
Windows 10/11, Server 2012-2022 Secure Boot Bypass via Integer Underflow
CVSS 8.0
CVE-2024-21466 MEDIUM
Qualcomm FastConnect 7800 Firmware - Information Disclosure via Sub-IE Length Parsing
CVSS 6.5
CVE-2024-6285 HIGH
Renesas arm-trusted-firmware - Memory Corruption
CVSS 7.5
CVE-2024-30070 HIGH
Windows Server 2012, 2016, 2019 DHCP Server Service Integer Underflow DoS
CVSS 7.5
CVE-2024-5256 MEDIUM
Sonos Era 100 Firmware - Unauthenticated Integer Underflow in SMB2 Message Handling
CVSS 4.3
CVE-2024-32975 MEDIUM
envoyproxy/envoy < 1.27.6 - Denial of Service via Integer Underflow in QuicStreamSequencerBuffer
CVSS 5.9
CVE-2024-35980 MEDIUM
Linux Kernel - Integer Overflow in TLBI RANGE Operand
CVSS 5.5
CVE-2024-30011 MEDIUM
Windows Server 2012, 2016, 2019, 2022 Hyper-V Integer Underflow DoS
CVSS 6.5
CVE-2024-30008 MEDIUM
Windows DWM Core Library - Info Disclosure
CVSS 5.5
CVE-2024-32040 HIGH
FreeRDP <3.5.0-2.11.6 - Integer Underflow
CVSS 8.1
CVE-2024-26913 HIGH
Linux Kernel - Integer Underflow in DRM AMD Display ODM Calculation
CVSS 7.8
CVE-2024-26828 MEDIUM
Linux Kernel 4.18-6.1.78, 6.2-6.6.17, 6.7-6.7.5 - Integer Underflow in CIFS Server Interface Parser
CVSS 6.7
CVE-2024-28945 HIGH
Microsoft OLE DB Driver for SQL Server 18.0.2-18.7.0002.0 - Remote Code Execution
CVSS 8.8
Details
Vulnerabilities 459