The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protec
An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to com
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada
Lexbor is a web browser engine library. Prior to 2.7.0, the ISO‑2022‑JP encoder in Lexbor fails to reset the temporary s
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allo
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a
In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix overflow when accumulating packets Ad
In the Linux kernel, the following vulnerability has been resolved: tipc: fix bc_ackers underflow on duplicate GRP_ACK_
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an i
An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) v
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.
An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to caus
FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,
Xcitium Client Security (XCS) before 13.8.2.10019 and Comodo Internet Security (CIS) through 12.3.4.8162 (fix expected b
TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection
U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over
libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ss
Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modu
gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes
FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_
The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only cl
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2,
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2,
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an impro
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 s
A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLeng
Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry o
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat d
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
In the Linux kernel, the following vulnerability has been resolved: erofs: fix unsigned underflow in z_erofs_lz4_handle
libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c d
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in Image
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request para
SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_multipart.c that allows
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM an
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resour
Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption
Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo
wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted m
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (li
OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a()
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and abov
Information Disclosure when processing wireless network channel switch information with improperly formatted length fiel
Frequently Asked Questions
What is CWE-191?
CWE-191 (CWE-191) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-191?
There are 272 CVE records associated with CWE-191 in our database. Of these, 28 are critical severity, 109 are high severity, and 81 are medium severity.
How can I protect against CWE-191 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-191 using AI-powered security agents.
Detect CWE-191 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-191 vulnerabilities across your infrastructure.
Get Started