Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-191

Integer Underflow (Wrap or Wraparound)

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

494
Assigned CVEs
78th
Commonality Rank
7.4
Avg CVSS
0.6%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-191 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
May 4, 2004
22 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

494 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-0497CRITICAL
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote atta
Feb 5, 20149.898YESYES
CVE-2022-0185HIGH
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters
Feb 11, 20228.477YESNO
CVE-2021-31956HIGH
Windows NTFS Elevation of Privilege Vulnerability
Jun 8, 20217.874YESNO
CVE-2024-38063CRITICAL
Windows TCP/IP Remote Code Execution Vulnerability
Aug 13, 20249.873NONO
CVE-2017-14496HIGH
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a
Oct 3, 20177.573NOYES
CVE-2020-36221HIGH
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c
Jan 26, 20217.570NONO
CVE-2023-31102HIGH
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
Nov 3, 20237.865NONO
CVE-2020-36228HIGH
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.
Jan 26, 20217.565NONO
CVE-2023-42118HIGH
Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim
May 3, 20248.855NONO
CVE-2004-0184MEDIUM
Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payl
May 4, 20045.054NOYES
View all 494 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
19%
5.0-5.9
16%
6.0-6.9
43%
26%
7.0-7.9
12%
11%
8.0-8.9
15%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
3 CVEs
0.6% of CVEs· 86th percentile
Metasploit
1 CVE
0.2% of CVEs· 80th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
1.8% of CVEs· 87th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products