TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compres
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4
gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs w
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an applica
An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cau
SumatraPDF is a multi-format reader for Windows. All versions contain an off-by-one error in the validation code that on
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential underflow in virtio_tra
osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulner
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Fix static_branch_dec() underflow f
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate minimum block_len in n
In the Linux kernel, the following vulnerability has been resolved: EFI/CPER: don't dump the entire memory region The
In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix PM runtime usage cou
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix transaction abort on set received ioctl
In the Linux kernel, the following vulnerability has been resolved: apparmor: avoid per-cpu hold underflow in aa_get_bu
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Reject zero-length property entries in
Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.
Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryptio
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1
nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingCon
Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adj
Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty enco
Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handlin
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards call
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0,
go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vu
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_lda
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0
Frequently Asked Questions
What is CWE-191?
CWE-191 (CWE-191) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-191?
There are 621 CVE records associated with CWE-191 in our database. Of these, 65 are critical severity, 283 are high severity, and 153 are medium severity.
How can I protect against CWE-191 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-191 using AI-powered security agents.
Detect CWE-191 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-191 vulnerabilities across your infrastructure.
Get Started