CWE-191: CWE-191

123
Total CVEs
19
Critical
76
High
7.6
Avg CVSS

Yearly Trend

2026
7
2025
45
2024
33
2023
21
2022
2

Top Affected Vendors

1 Microsoft 24
2 Linux 20
3 Adobe 19
4 Debian 7
5 Fedoraproject 4
6 Eclipse 4
7 Qualcomm 4
8 Google 2
9 7 Zip 2
10 Nasa 2

All CWE-191 CVEs (123)

CVE-2025-30356
9.8

A heap buffer overflow vulnerability in CryptoLib's SDLS-EP implementation allows attackers to craft malicious frames that cause negative payload leng...

Apr 1, 2025
CVE-2025-29909
9.8

A heap buffer overflow vulnerability in CryptoLib's Crypto_TC_ApplySecurity() function allows attackers to craft malicious Telecommand frames that cau...

Mar 17, 2025
CVE-2018-9388
9.8

CVE-2018-9388 is a critical memory corruption vulnerability in STMicroelectronics touchscreen drivers for Android devices. It allows attackers to exec...

Dec 5, 2024
CVE-2024-38063
9.8

This critical vulnerability in Windows TCP/IP stack allows remote attackers to execute arbitrary code without authentication by sending specially craf...

Aug 13, 2024
CVE-2024-38074
9.8

CVE-2024-38074 is a critical remote code execution vulnerability in Windows Remote Desktop Licensing Service that allows unauthenticated attackers to ...

Jul 9, 2024
CVE-2024-0808
9.8

This vulnerability is an integer underflow in Chrome's WebUI that allows remote attackers to trigger heap corruption via malicious files. It affects G...

Jan 24, 2024
CVE-2023-32653
9.8

This critical vulnerability in Accusoft ImageGear allows attackers to execute arbitrary code by tricking users into opening specially crafted maliciou...

Sep 25, 2023
CVE-2023-32014
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General M...

Jun 14, 2023
CVE-2023-28250
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General M...

Apr 11, 2023
CVE-2023-21708
9.8

This is a critical Remote Procedure Call Runtime vulnerability that allows unauthenticated attackers to execute arbitrary code remotely on affected Wi...

Mar 14, 2023
CVE-2021-40589
9.8

CVE-2021-40589 is an integer underflow vulnerability in ZAngband's zangband-data 2.7.5 that occurs when processing bitmap file headers. This allows at...

Jun 8, 2022
CVE-2021-1920
9.8

CVE-2021-1920 is an integer underflow vulnerability in Qualcomm Snapdragon chipsets' RTCP packet handling that allows remote code execution. Attackers...

Sep 8, 2021
CVE-2021-21811
9.8

CVE-2021-21811 is a critical heap buffer overflow vulnerability in Xmill 0.7's XML parser that allows memory corruption via specially crafted XML file...

Aug 31, 2021
CVE-2021-28027
9.8

This vulnerability in the bam crate for Rust allows integer underflow and out-of-bounds write during bgzip block loading. Attackers can exploit this t...

Mar 5, 2021
CVE-2020-28194
9.8

This CVE describes an integer underflow vulnerability in accel-ppp's RADIUS packet processing that allows arbitrary code execution when an attacker-co...

Feb 1, 2021
CVE-2020-3691
9.8

This vulnerability allows integer underflow in Qualcomm Snapdragon audio processing, potentially leading to out-of-bounds memory access. Attackers cou...

Jan 21, 2021
CVE-2025-2523
9.4

An integer underflow vulnerability in Honeywell Experion PKS and OneWireless WDM's Control Data Access component allows attackers to manipulate commun...

Jul 10, 2025
CVE-2024-57823
9.3

CVE-2024-57823 is an integer underflow vulnerability in the Raptor RDF Syntax Library's turtle parser that can lead to memory corruption when processi...

Jan 10, 2025
CVE-2024-10838
9.1

CVE-2024-10838 is an integer underflow vulnerability in Eclipse Cyclone DDS during deserialization that allows unauthenticated attackers to read out-o...

Mar 12, 2025
CVE-2024-11950
8.8

This vulnerability allows remote attackers to execute arbitrary code on XnSoft XnView Classic installations by tricking users into opening malicious R...

Dec 12, 2024
CVE-2024-28930
8.8

This vulnerability in Microsoft ODBC Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially ...

Apr 9, 2024
CVE-2024-26244
8.8

This vulnerability in Microsoft WDAC OLE DB provider for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending s...

Apr 9, 2024
CVE-2023-35387
8.8

This vulnerability in the Windows Bluetooth A2DP driver allows an attacker to gain SYSTEM-level privileges on affected systems. It affects Windows dev...

Aug 8, 2023
CVE-2023-24864
8.8

This vulnerability allows attackers to exploit Microsoft PostScript and PCL6 Class Printer Drivers to gain SYSTEM-level privileges on Windows systems....

Mar 14, 2023
CVE-2023-21684
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems using Microsoft PostScript and PCL6 Class Printer Drivers. Attackers c...

Feb 14, 2023
CVE-2021-20240
8.8

CVE-2021-20240 is an integer overflow vulnerability in gdk-pixbuf's GIF image parser that allows out-of-bounds writes when processing malicious GIF fi...

May 28, 2021
CVE-2024-54028
8.4

An integer underflow vulnerability in catdoc's OLE Document DIFAT parser allows heap-based memory corruption when processing specially crafted files. ...

Jun 2, 2025
CVE-2023-21630
8.4

This vulnerability allows memory corruption in Qualcomm's multimedia framework due to integer overflow when synx bind is called with synx signal. It a...

Apr 13, 2023
CVE-2021-3323
8.3

This CVE describes an integer underflow vulnerability in the 6LoWPAN IPHC header uncompression functionality in Zephyr RTOS. An attacker could exploit...

Oct 12, 2021
CVE-2025-1924
8.2

A vulnerability in Yokogawa's Vnet/IP Interface Package allows attackers to cause denial of service or execute arbitrary code by sending maliciously c...

Feb 13, 2026
CVE-2025-11931
8.2

An integer underflow vulnerability in wolfSSL's XChaCha20-Poly1305 decryption function allows attackers to cause out-of-bounds memory access when proc...

Nov 21, 2025
CVE-2025-3947
8.2

This CVE describes an integer underflow vulnerability in Honeywell Experion PKS Control Data Access (CDA) component. Attackers can manipulate input da...

Jul 10, 2025
CVE-2026-3172
8.1

A buffer overflow vulnerability in the parallel HNSW index build functionality of pgvector allows authenticated database users to read sensitive data ...

Feb 25, 2026
CVE-2025-62291
8.1

This vulnerability in strongSwan's eap-mschapv2 plugin allows a malicious EAP-MSCHAPv2 server to trigger an integer underflow and heap-based buffer ov...

Jan 16, 2026
CVE-2022-28733
8.1

CVE-2022-28733 is an integer underflow vulnerability in GRUB2's network stack that allows remote attackers to cause buffer overflow via specially craf...

Jul 20, 2023
CVE-2024-37975
8.0

This vulnerability allows attackers to bypass Secure Boot protections on affected systems, potentially enabling them to load and execute unauthorized ...

Jul 9, 2024
CVE-2025-61835
7.8

Substance3D Stager versions 3.1.5 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user opens a...

Nov 11, 2025
CVE-2025-61826
7.8

Adobe Illustrator on iPad versions 3.0.9 and earlier contain an integer underflow vulnerability that could allow attackers to execute arbitrary code w...

Nov 11, 2025
CVE-2025-61836
7.8

Adobe Illustrator on iPad versions 3.0.9 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user ...

Nov 11, 2025
CVE-2025-49532
7.8

This CVE describes an integer underflow vulnerability in Adobe Illustrator that could allow arbitrary code execution when a user opens a malicious fil...

Jul 8, 2025
CVE-2025-43546
7.8

Adobe Bridge versions 15.0.3, 14.1.6 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user open...

May 13, 2025
CVE-2025-43555
7.8

An integer underflow vulnerability in Adobe Animate allows arbitrary code execution when a user opens a malicious file. This affects users of Adobe An...

May 13, 2025
CVE-2025-21160
7.8

Adobe Illustrator versions 29.1, 28.7.3 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user o...

Feb 11, 2025
CVE-2025-21156
7.8

An integer underflow vulnerability in Adobe InCopy allows arbitrary code execution when a user opens a malicious file. This affects users of InCopy ve...

Feb 11, 2025
CVE-2025-21158
7.8

An integer underflow vulnerability in Adobe InDesign allows arbitrary code execution when a user opens a malicious file. This affects users of InDesig...

Feb 11, 2025
CVE-2025-21135
7.8

Adobe Animate versions 24.0.6, 23.0.9 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user ope...

Jan 14, 2025
CVE-2025-21133
7.8

Adobe Illustrator on iPad versions 3.0.7 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user ...

Jan 14, 2025
CVE-2025-21134
7.8

Adobe Illustrator on iPad versions 3.0.7 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user ...

Jan 14, 2025
CVE-2025-21122
7.8

Adobe Photoshop Desktop versions 25.12, 26.1 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a u...

Jan 14, 2025
CVE-2024-53955
7.8

CVE-2024-53955 is an integer underflow vulnerability in Adobe Bridge that could allow arbitrary code execution when a user opens a malicious file. Thi...

Dec 10, 2024

About CWE-191 (CWE-191)

Our database tracks 123 CVEs classified as CWE-191, with 19 rated critical and 76 rated high severity. The average CVSS score for CWE-191 vulnerabilities is 7.6.

External reference: View CWE-191 on MITRE CWE →

Monitor CWE-191 Vulnerabilities

Get alerted when new CWE-191 CVEs affect your infrastructure.

Start Monitoring Free