CWE-191: CWE-191

121
Total CVEs
19
Critical
74
High
7.6
Avg CVSS

Yearly Trend

2026
7
2025
45
2024
33
2023
21
2022
2

Top Affected Vendors

1 Microsoft 24
2 Linux 20
3 Adobe 19
4 Debian 7
5 Fedoraproject 4
6 Eclipse 4
7 Qualcomm 4
8 Google 2
9 7 Zip 2
10 Nasa 2

All CWE-191 CVEs (121)

CVE-2024-52984
7.8

Adobe Animate versions 23.0.8, 24.0.5 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user ope...

Dec 10, 2024
CVE-2024-52986
7.8

Adobe Animate versions 23.0.8, 24.0.5 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user ope...

Dec 10, 2024
CVE-2024-11477
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of 7-Zip when processing malicious Zstanda...

Nov 22, 2024
CVE-2024-53061
7.8

A buffer overflow vulnerability in the Linux kernel's s5p-jpeg media driver allows local attackers to cause memory corruption. This affects systems us...

Nov 19, 2024
CVE-2024-47425
7.8

Adobe Framemaker versions 2020.6, 2022.4 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user ...

Oct 9, 2024
CVE-2024-46759
7.8

This CVE-2024-46759 is an integer underflow vulnerability in the Linux kernel's adc128d818 hardware monitoring driver. When users write large negative...

Sep 18, 2024
CVE-2024-41857
7.8

Adobe Illustrator versions 28.6, 27.9.5 and earlier contain an integer underflow vulnerability that could allow arbitrary code execution when a user o...

Sep 13, 2024
CVE-2024-38050
7.8

This vulnerability allows an authenticated attacker to elevate privileges on Windows systems by exploiting the Workstation Service. It affects Windows...

Jul 9, 2024
CVE-2024-26913
7.8

This CVE describes a vulnerability in the Linux kernel's AMD display driver where missing ODM (Output Data Mux) calculations during pipe split policy ...

Apr 17, 2024
CVE-2023-31102
7.8

This vulnerability in 7-Zip's PPMd7 compression module allows attackers to craft malicious 7Z archives that trigger an integer underflow, leading to i...

Nov 3, 2023
CVE-2023-36796
7.8

This vulnerability in Visual Studio allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted ...

Sep 12, 2023
CVE-2023-26421
7.8

This CVE describes an integer underflow/wraparound vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a...

Apr 12, 2023
CVE-2023-28293
7.8

This Windows kernel vulnerability allows local attackers to escalate privileges from a lower-privileged account to SYSTEM-level access. It affects Win...

Apr 11, 2023
CVE-2023-28272
7.8

CVE-2023-28272 is a Windows kernel elevation of privilege vulnerability that allows authenticated attackers to execute arbitrary code with SYSTEM priv...

Apr 11, 2023
CVE-2023-21815
7.8

CVE-2023-21815 is a remote code execution vulnerability in Visual Studio that allows attackers to execute arbitrary code on affected systems. This aff...

Feb 14, 2023
CVE-2022-22715
7.8

CVE-2022-22715 is a Windows Named Pipe File System elevation of privilege vulnerability that allows authenticated attackers to gain SYSTEM-level privi...

Feb 9, 2022
CVE-2021-31956
7.8

CVE-2021-31956 is a Windows NTFS elevation of privilege vulnerability that allows authenticated attackers to gain SYSTEM-level privileges on affected ...

Jun 8, 2021
CVE-2021-3472
7.8

CVE-2021-3472 is an integer underflow vulnerability in xorg-x11-server that allows local attackers to escalate privileges on affected systems. This fl...

Apr 26, 2021
CVE-2021-27486
7.8

CVE-2021-27486 is an integer underflow vulnerability in FATEK Automation WinProladder PLC programming software that can lead to out-of-bounds writes a...

Apr 12, 2021
CVE-2025-67269
7.5

An integer underflow vulnerability in gpsd's NAVCOM packet parser causes a denial of service condition. When processing malicious packets, the parser ...

Jan 2, 2026
CVE-2025-64076
7.5

Two vulnerabilities in cbor2's C extension allow remote attackers to cause denial of service through process crashes or memory exhaustion. Attackers c...

Nov 18, 2025
CVE-2025-1991
7.5

IBM Informix Dynamic Server contains an integer underflow vulnerability when processing network packets, allowing remote attackers to cause denial of ...

Jun 28, 2025
CVE-2025-4948
7.5

An integer underflow vulnerability in libsoup's soup_multipart_new_from_message() function allows specially crafted multipart messages to cause memory...

May 19, 2025
CVE-2025-2258
7.5

This vulnerability in Eclipse ThreadX NetX Duo's HTTP server allows attackers to cause integer underflow and denial of service by sending specially cr...

Apr 6, 2025
CVE-2025-0728
7.5

An integer underflow vulnerability in NetX HTTP server functionality of Eclipse ThreadX NetX Duo allows attackers to cause denial of service by sendin...

Feb 21, 2025
CVE-2025-0727
7.5

An integer underflow vulnerability in NetX HTTP server functionality of Eclipse ThreadX NetX Duo allows attackers to cause denial of service by sendin...

Feb 21, 2025
CVE-2025-21276
EPSS 15.4% 7.5

This vulnerability in Windows MapUrlToZone function allows attackers to cause denial of service by crashing affected systems. It affects Windows syste...

Jan 14, 2025
CVE-2024-56375
7.5

An integer underflow vulnerability in FORT RPKI validator versions 1.6.3 and 1.6.4 allows a malicious RPKI repository to cause a denial of service by ...

Dec 22, 2024
CVE-2024-47545
7.5

This CVE describes an integer underflow vulnerability in GStreamer's qtdemux component that can lead to out-of-bounds memory reads. Attackers could ex...

Dec 12, 2024
CVE-2024-6285
7.5

An integer underflow vulnerability in Renesas ARM Trusted Firmware's image range check calculations could allow attackers to bypass address restrictio...

Jun 24, 2024
CVE-2024-30070
7.5

This vulnerability in the DHCP Server service allows an attacker to send specially crafted packets that cause a denial of service (DoS) condition. The...

Jun 11, 2024
CVE-2023-47360
7.5

CVE-2023-47360 is an integer underflow vulnerability in VLC media player's MMS protocol handler that can cause incorrect packet length calculations. T...

Nov 7, 2023
CVE-2023-22308
7.5

An integer underflow vulnerability in SoftEther VPN's vpnserver OvsProcessData functionality allows attackers to cause denial of service by sending sp...

Oct 12, 2023
CVE-2023-35790
7.5

This vulnerability in libjxl (JPEG XL library) allows an integer underflow during patch dictionary decoding, which can cause denial of service through...

Jun 16, 2023
CVE-2023-31137
7.5

A remotely exploitable integer underflow vulnerability in MaraDNS allows attackers to cause Denial of Service by sending specially crafted DNS packets...

May 9, 2023
CVE-2023-28247
7.5

This vulnerability in Windows Network File System (NFS) allows an attacker to read sensitive information from memory that should be protected. It affe...

Apr 11, 2023
CVE-2021-22379
7.5

This CVE describes an integer underflow vulnerability in Huawei smartphones' Samgr component, which could allow an attacker to cause a denial-of-servi...

Aug 2, 2021
CVE-2021-33536
7.5

This vulnerability allows unauthenticated attackers to send specially crafted packets to Weidmueller Industrial WLAN devices, causing an integer under...

Jun 25, 2021
CVE-2021-37706
7.3

CVE-2021-37706 is an integer underflow vulnerability in PJSIP's STUN message processing that allows remote code execution. Attackers on the same netwo...

Dec 22, 2021
CVE-2024-26208
7.2

This vulnerability in Microsoft Message Queuing (MSMQ) allows remote attackers to execute arbitrary code on affected systems by sending specially craf...

Apr 9, 2024
CVE-2022-49278
7.1

This CVE addresses an integer underflow vulnerability in the Linux kernel's remoteproc subsystem. If exploited, it could allow local attackers to caus...

Feb 26, 2025
CVE-2023-44378
7.1

This vulnerability in the gnark zk-SNARK library allows for multiple valid bit decompositions of certain in-circuit values due to field overflow. This...

Oct 9, 2023
CVE-2023-39413
7.0

This vulnerability allows attackers to execute arbitrary code or cause denial of service by tricking users into opening a malicious .lxt2 file in GTKW...

Jan 8, 2024
CVE-2025-48021
6.5

A vulnerability in Yokogawa's Vnet/IP Interface Package allows remote attackers to cause denial of service by sending maliciously crafted packets, whi...

Feb 13, 2026
CVE-2024-21466
6.5

This vulnerability allows information disclosure when parsing sub-IE length during new IE generation in Qualcomm components. It affects devices using ...

Jul 1, 2024
CVE-2024-30011
6.5

This vulnerability in Windows Hyper-V allows an authenticated attacker on a guest virtual machine to cause a denial of service condition on the host s...

May 14, 2024
CVE-2026-25532
6.3

This vulnerability in ESP-IDF's WPS Enrollee implementation allows integer underflow when processing malformed EAP-WSC packets with truncated payloads...

Feb 4, 2026
CVE-2023-53679
5.5

This CVE describes an integer underflow vulnerability in the MediaTek MT7601U WiFi driver in the Linux kernel. An attacker could manipulate network pa...

Oct 7, 2025
CVE-2025-39928
5.5

A vulnerability in the Linux kernel's i2c driver for Realtek RTL9300 chips allows improper handling of zero-length data transfers. This can cause unin...

Oct 1, 2025
CVE-2023-53226
5.5

This CVE-2023-53226 is an out-of-bounds (OOB) and integer underflow vulnerability in the mwifiex WiFi driver in the Linux kernel. It allows attackers ...

Sep 15, 2025

About CWE-191 (CWE-191)

Our database tracks 121 CVEs classified as CWE-191, with 19 rated critical and 74 rated high severity. The average CVSS score for CWE-191 vulnerabilities is 7.6.

External reference: View CWE-191 on MITRE CWE →

Monitor CWE-191 Vulnerabilities

Get alerted when new CWE-191 CVEs affect your infrastructure.

Start Monitoring Free