Skip to main content

CWE archive

CWE-191 CVEs

Programmatic archive

501 CVEs tagged with CWE-19157 Critical, 265 High, 161 Medium, 18 Low, 0 Unrated.

CVE-2026-13308

Published Jul 29, 2026

Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54345

Published Jul 28, 2026

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-51254

Published Jul 28, 2026

schreibfaul1 ESP32-audioI2S v3.4.5 has an integer underflow vulnerability in the MP3Decoder::GetBits() function of the MP3 decoder due to unchecked bit reading operations. The lac…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-42495

Published Jul 28, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfs…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54890

Published Jul 27, 2026

Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Overflow, Excessive Allocation.…

CVSS 8.2 · High
evidence mentions
5
Buzz score
30.9

CVE-2026-66033

Published Jul 24, 2026

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a m…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-45813

Published Jul 24, 2026

Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service  "Add Source" and "Modify So…

CVSS 8.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-65704

Published Jul 23, 2026

FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 f…

CVSS 7.3 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-48029

Published Jul 22, 2026

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinat…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-44251

Published Jul 17, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40955

Published Jul 15, 2026

CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total contro…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40954

Published Jul 15, 2026

CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total contro…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54982

Published Jul 14, 2026

Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

CVSS 8.8 · High
evidence mentions
7
Buzz score
38.3

CVE-2026-50300

Published Jul 14, 2026

Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-51540

Published Jul 13, 2026

OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-29008

Published Jul 8, 2026

U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the boot…

CVSS 8.7 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort
Showing 1-25 of 501 CVEsPage 1 of 21