The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Volume of CVEs assigned to CWE-191 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
494 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0497CRITICAL Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote atta | Feb 5, 2014 | 9.8 | 98 | YES | YES |
CVE-2022-0185HIGH A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters | Feb 11, 2022 | 8.4 | 77 | YES | NO |
CVE-2021-31956HIGH Windows NTFS Elevation of Privilege Vulnerability | Jun 8, 2021 | 7.8 | 74 | YES | NO |
CVE-2024-38063CRITICAL Windows TCP/IP Remote Code Execution Vulnerability | Aug 13, 2024 | 9.8 | 73 | NO | NO |
CVE-2017-14496HIGH Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a | Oct 3, 2017 | 7.5 | 73 | NO | YES |
CVE-2020-36221HIGH An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c | Jan 26, 2021 | 7.5 | 70 | NO | NO |
CVE-2023-31102HIGH Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. | Nov 3, 2023 | 7.8 | 65 | NO | NO |
CVE-2020-36228HIGH An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service. | Jan 26, 2021 | 7.5 | 65 | NO | NO |
CVE-2023-42118HIGH Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim | May 3, 2024 | 8.8 | 55 | NO | NO |
CVE-2004-0184MEDIUM Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payl | May 4, 2004 | 5.0 | 54 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.