Windows iSCSI Service Denial of Service Vulnerability
Windows Network File System Information Disclosure Vulnerability
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc
MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process
An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can le
DHCP Server Service Denial of Service Vulnerability
An integer underflow vulnerability exists in the vpnserver OvsProcessData functionality of SoftEther VPN 5.01.9674 and 5
Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.
gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. This issue aff
An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially craf
ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Lin
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi
In keyinstall, there is a possible information disclosure due to an integer overflow. This could lead to local informati
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
ZAngband zangband-data 2.7.5 is affected by an integer underflow vulnerability in src/tk/plat.c through the variable fil
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Sp
Azure RTOS USBX is a high-performance USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated wit
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap
Named Pipe File System Elevation of Privilege Vulnerability
An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file.
Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and
There is an integer underflow vulnerability in the atcmdserver module. Successful exploitation of this vulnerability may
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause an integer under
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers
Allowing long password leads to denial of service in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerab
A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integra
A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the contr
In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds rea
In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. Thi
An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when usin
In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could lead to local escalat
Frontier is Substrate's Ethereum compatibility layer. Prior to commit number `8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664`,
The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of lon
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended form
Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2
A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mapping
An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who suppl
libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples
In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overf
Frequently Asked Questions
What is CWE-191?
CWE-191 (CWE-191) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-191?
There are 621 CVE records associated with CWE-191 in our database. Of these, 65 are critical severity, 283 are high severity, and 153 are medium severity.
How can I protect against CWE-191 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-191 using AI-powered security agents.
Detect CWE-191 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-191 vulnerabilities across your infrastructure.
Get Started