A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when comp
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to befo
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containin
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16
In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used b
An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain l
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service again
Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit d7f55b38, contain an out-of-bounds read in LightDB
CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 1
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 1
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache
An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal
An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads
OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a
An integer underflow vulnerability in Silicon Labs Secure NCP host implementation allows a buffer overread via a special
An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs
pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior
Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously c
An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/captu
An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker t
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated a
An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker t
In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix overflow inside virtnet_rq_alloc W
In the Linux kernel, the following vulnerability has been resolved: NFSD: prevent underflow in nfssvc_decode_writeargs(
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been ide
The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Con
In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser
An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This m
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issu
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix OOB and integer underflow when r
An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent rep
An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially cra
In the Linux kernel, the following vulnerability has been resolved: wifi: mt7601u: fix an integer underflow Fix an int
The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). A
Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a cal
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabili
Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability t
Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability t
Animate versions 24.0.6, 23.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnera
InCopy versions 20.0, 19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that co
Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability th
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - add param check for RSA Reject reque
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - add param check for DH Reject reques
Frequently Asked Questions
What is CWE-191?
CWE-191 (CWE-191) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-191?
There are 621 CVE records associated with CWE-191 in our database. Of these, 65 are critical severity, 283 are high severity, and 153 are medium severity.
How can I protect against CWE-191 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-191 using AI-powered security agents.
Detect CWE-191 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-191 vulnerabilities across your infrastructure.
Get Started