Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-191

MITRE ↗

CWE-191

65
CRITICAL
283
HIGH
153
MEDIUM
11
LOW
525 CVEs · Page 8/11
7.5
CVE-2023-21527

Windows iSCSI Service Denial of Service Vulnerability

7.5
CVE-2023-28247

Windows Network File System Information Disclosure Vulnerability

7.5
CVE-2023-24820

RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc

7.5
CVE-2023-24821

RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc

7.5
CVE-2023-31137

MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely

7.5
CVE-2023-24817

RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process

7.5
CVE-2023-35790

An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can le

7.5
CVE-2023-38162

DHCP Server Service Denial of Service Vulnerability

7.5
CVE-2023-22308

An integer underflow vulnerability exists in the vpnserver OvsProcessData functionality of SoftEther VPN 5.01.9674 and 5

7.5
CVE-2023-47360

Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.

7.1
CVE-2023-44378

gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit

6.5
CVE-2023-36909

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

6.3
CVE-2023-5753

Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c

5.9
CVE-2023-39350

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. This issue aff

5.9
CVE-2023-43628

An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially craf

5.9
CVE-2023-48298

ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports

5.5
CVE-2022-44444

In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

5.5
CVE-2023-0469

A use-after-free flaw was found in io_uring/filetable.c in io_install_fixed_file in the io_uring subcomponent in the Lin

5.5
CVE-2022-38681

In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.

5.3
CVE-2023-40181

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versi

4.4
CVE-2023-20635

In keyinstall, there is a possible information disclosure due to an integer overflow. This could lead to local informati

4.3
CVE-2023-24911

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

9.8
CVE-2021-40589

ZAngband zangband-data 2.7.5 is affected by an integer underflow vulnerability in src/tk/plat.c through the variable fil

8.8
CVE-2022-24046

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Sp

8.6
CVE-2022-39293

Azure RTOS USBX is a high-performance USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated wit

8.4
CVE-2022-0185 KEV

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio

7.8
CVE-2022-23613

xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap

7.8
CVE-2022-22715

Named Pipe File System Elevation of Privilege Vulnerability

7.8
CVE-2022-27492

An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file.

7.6
CVE-2022-36063

Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and

7.5
CVE-2021-40054

There is an integer underflow vulnerability in the atcmdserver module. Successful exploitation of this vulnerability may

7.5
CVE-2021-44489

An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause an integer under

7.5
CVE-2021-44509

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers

7.5
CVE-2022-1698

Allowing long password leads to denial of service in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerab

7.5
CVE-2022-2335

A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integra

7.5
CVE-2022-37301

A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the contr

7.5
CVE-2022-20483

In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds rea

7.5
CVE-2022-20516

In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. Thi

6.7
CVE-2022-30787

An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when usin

6.6
CVE-2022-20073

In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could lead to local escalat

6.5
CVE-2022-21685

Frontier is Substrate's Ethereum compatibility layer. Prior to commit number `8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664`,

6.5
CVE-2021-25121

The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of lon

6.5
CVE-2022-3165

An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended form

5.6
CVE-2022-39343

Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2

5.5
CVE-2022-23034

A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mapping

5.5
CVE-2022-0544

An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read

5.5
CVE-2022-29204

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem

5.5
CVE-2022-2867

libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who suppl

5.5
CVE-2022-2869

libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples

5.5
CVE-2022-20393

In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overf

Frequently Asked Questions

What is CWE-191?

CWE-191 (CWE-191) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-191?

There are 621 CVE records associated with CWE-191 in our database. Of these, 65 are critical severity, 283 are high severity, and 153 are medium severity.

How can I protect against CWE-191 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-191 using AI-powered security agents.

Detect CWE-191 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-191 vulnerabilities across your infrastructure.

Get Started