The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
501 vulnerabilities with CWE-191
CVE-2025-21376
HIGH
Windows LDAP - Remote Code Execution via Race Condition
CVSS 8.1
CVE-2025-21160
HIGH
Adobe Illustrator < 28.7.4 - Integer Underflow leading to Arbitrary Code Execution
CVSS 7.8
CVE-2025-21156
HIGH
InCopy < 19.5.2 - Integer Underflow leading to Arbitrary Code Execution
CVSS 7.8
CVE-2025-21158
HIGH
Adobe InDesign < 19.5.2 - Integer Underflow to Arbitrary Code Execution
CVSS 7.8
CVE-2025-21135
HIGH
Adobe Animate < 23.0.10 - Integer Underflow Leading to Arbitrary Code Execution
CVSS 7.8
CVE-2025-21134
HIGH
Illustrator on iPad < 3.0.8 - Integer Underflow Leading to Arbitrary Code Execution
CVSS 7.8
CVE-2025-21133
HIGH
Illustrator on iPad < 3.0.8 - Integer Underflow Leading to Arbitrary Code Execution
CVSS 7.8
CVE-2025-21122
HIGH
Photoshop 25.0-25.12, 26.0-26.1 - Integer Underflow Leading to Arbitrary Code Execution via Malicious File
CVSS 7.8
CVE-2025-21276
HIGH
Windows 10 1507-24H2 and Windows Server 2008-2012 - Denial of Service via MapUrlToZone Integer Underflow
CVSS 7.5
CVE-2024-54028
HIGH
catdoc 0.95 - Heap-Based Memory Corruption
CVSS 8.4
CVE-2024-50597
MEDIUM
STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0 - Denial of Service via HTTP Server PUT Request Integer Underflow
CVSS 4.3
CVE-2024-50596
MEDIUM
STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0 - Denial of Service via HTTP Server PUT Request Integer Underflow
CVSS 4.3
CVE-2024-50595
MEDIUM
STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0 - Denial of Service via HTTP Server PUT Request Integer Underflow
CVSS 4.3
CVE-2024-50594
MEDIUM
STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0 - Denial of Service via HTTP Server PUT Request Integer Underflow
CVSS 4.3
CVE-2024-10838
CRITICAL
Eclipse Cyclone Data Distribution Service < 0.10.5 - Unauthenticated Integer Underflow via Deserialization
CVSS 9.1
CVE-2024-57843
MEDIUM
Linux Kernel < 6.6.66, 6.6.0-6.6.66, 6.7.0-6.12.5, 6.12.5-6.12.*, 6.13 - Integer Underflow in virtnet_rq_alloc
CVSS 5.5
CVE-2024-57823
CRITICAL
raptor_rdf_syntax_library <= 2.0.16 - Integer Underflow in URI Normalization
CVSS 9.3
CVE-2024-55627
MEDIUM
Suricata < 7.0.8 - Integer Underflow in TCP Stream Handling
CVSS 5.9
CVE-2024-56375
HIGH
nicmx fort_validator 1.6.3-1.6.4 - Integer Underflow via Empty Manifest FileList
CVSS 7.5
CVE-2024-49103
MEDIUM
Windows WwanSvc - Out-of-bounds Read
CVSS 4.3
CVE-2024-49077
MEDIUM
Windows Mobile Broadband Driver - Elevation of Privilege via Out-of-bounds Read
CVSS 6.8
CVE-2024-47606
CRITICAL
GStreamer < 1.24.10 - Integer Underflow via qtdemux_parse_theora_extension
CVSS 9.8
CVE-2024-47546
HIGH
GStreamer <1.24.10 - Memory Corruption
CVSS 7.5
CVE-2024-47545
HIGH
GStreamer <1.24.10 - Buffer Overflow
CVSS 7.5
CVE-2024-11950
HIGH
XnView Classic - Remote Code Execution via RWZ File Parsing Integer Underflow
CVSS 8.8
Details
Vulnerabilities
501