CWE-191: CWE-191

122
Total CVEs
19
Critical
75
High
7.6
Avg CVSS

Yearly Trend

2026
7
2025
45
2024
33
2023
21
2022
2

Top Affected Vendors

1 Microsoft 24
2 Linux 20
3 Adobe 19
4 Debian 7
5 Fedoraproject 4
6 Eclipse 4
7 Qualcomm 4
8 Google 2
9 7 Zip 2
10 Nasa 2

All CWE-191 CVEs (122)

CVE-2023-53226
5.5

This CVE-2023-53226 is an out-of-bounds (OOB) and integer underflow vulnerability in the mwifiex WiFi driver in the Linux kernel. It allows attackers ...

Sep 15, 2025
CVE-2023-53189
5.5

This is a Linux kernel vulnerability in the IPv6 address configuration module that could cause a reference count underflow for network interface devic...

Sep 15, 2025
CVE-2025-38463
5.5

A Linux kernel vulnerability in TCP data handling allows integer overflow in sk_forward_alloc memory tracking. This can cause memory accounting errors...

Jul 25, 2025
CVE-2025-38200
5.5

A Linux kernel vulnerability in the i40e network driver allows integer underflow when processing specific device input, leading to MMIO write access t...

Jul 4, 2025
CVE-2025-38161
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem, specifically in the mlx5 driver ...

Jul 3, 2025
CVE-2022-50036
5.5

This CVE describes an integer underflow vulnerability in the Linux kernel's sun4i DRM DSI driver. When computing packet sizes with short sync pulses, ...

Jun 18, 2025
CVE-2022-49650
5.5

This CVE involves an unbalanced runtime power management (PM) issue in the Linux kernel's BAM DMA driver for Qualcomm chips. It causes PM underflow wh...

Feb 26, 2025
CVE-2022-49563
5.5

This vulnerability in the Linux kernel's QAT crypto driver allows an attacker to trigger an integer underflow when processing RSA encryption/decryptio...

Feb 26, 2025
CVE-2022-49208
5.5

This CVE addresses an integer underflow vulnerability in the Linux kernel's RDMA/irdma driver. If exploited, it could lead to kernel memory corruption...

Feb 26, 2025
CVE-2022-49199
5.5

This CVE-2022-49199 is an integer underflow vulnerability in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem. It allows local attacker...

Feb 26, 2025
CVE-2024-50290
5.5

A vulnerability in the Linux kernel's cx24116 media driver could allow integer underflow when reading SNR registers fails, returning negative values. ...

Nov 19, 2024
CVE-2024-43867
5.5

This CVE describes a refcount underflow vulnerability in the nouveau DRM driver in the Linux kernel. When the nouveau_bo_ref() function is called on a...

Aug 21, 2024
CVE-2021-47555
5.5

A Linux kernel vulnerability in the VLAN subsystem causes a reference counter underflow when removing a physical network device that has VLAN interfac...

May 24, 2024
CVE-2023-52705
5.5

A vulnerability in the Linux kernel's nilfs2 filesystem allows underflow in superblock position calculations when using devices smaller than 4096 byte...

May 21, 2024
CVE-2024-30008
5.5

This vulnerability in the Windows Desktop Window Manager (DWM) Core Library allows an attacker to read sensitive information from memory. It affects W...

May 14, 2024
CVE-2026-27710
5.0

A denial-of-service vulnerability exists in NanaZip's .NET Single File Application parser where a crafted archive bundle can trigger an integer underf...

Feb 26, 2026
CVE-2025-23335
4.4

NVIDIA Triton Inference Server contains an integer underflow vulnerability in its TensorRT backend that could allow attackers to cause denial of servi...

Aug 6, 2025
CVE-2024-50596
4.3

An integer underflow vulnerability in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL allows attackers to cause denia...

Apr 2, 2025
CVE-2024-50594
4.3

An integer underflow vulnerability in STMicroelectronics X-CUBE-AZRTOS-WL HTTP server PUT request handling allows denial of service attacks. Attackers...

Apr 2, 2025
CVE-2024-20474
4.3

An integer underflow vulnerability in IKEv2 processing in Cisco Secure Client (formerly AnyConnect) allows unauthenticated remote attackers to crash t...

Oct 23, 2024
CVE-2024-5256
4.3

An integer underflow vulnerability in SMB2 message handling on Sonos Era 100 smart speakers allows network-adjacent attackers to read sensitive memory...

Jun 6, 2024
CVE-2025-59368
N/A

An integer underflow vulnerability in Aicloud allows authenticated attackers to send crafted requests that could crash the device. This affects ASUS r...

Nov 25, 2025

About CWE-191 (CWE-191)

Our database tracks 122 CVEs classified as CWE-191, with 19 rated critical and 75 rated high severity. The average CVSS score for CWE-191 vulnerabilities is 7.6.

External reference: View CWE-191 on MITRE CWE →

Monitor CWE-191 Vulnerabilities

Get alerted when new CWE-191 CVEs affect your infrastructure.

Start Monitoring Free