Possible out of bound memory access in audio due to integer underflow while processing modified contents in Snapdragon A
Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length fie
An issue was discovered in the bam crate before 0.1.3 for Rust. There is an integer underflow and out-of-bounds write du
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A
Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapd
Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Sn
A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can oc
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A s
Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow f
Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap
Integer Underflow in 6LoWPAN IPHC Header Uncompression in Zephyr. Zephyr versions >= >=2.4.0 contain Integer Underflow (
FATEK Automation WinProladder Versions 3.30 and prior is vulnerable to an integer underflow, which may cause an out-of-b
A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead
Windows NTFS Elevation of Privilege Vulnerability
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertio
An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Ass
An integer underflow has been found in the latest version of ZCFees. The variables 'currPeriodIdx' and 'lastPeriodExecId
An issue was discovered in Contiki through 3.0. When sending an ICMPv6 error message because of invalid extension header
Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allow
An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, improper v
In Weidmueller Industrial WLAN devices in multiple versions an exploitable denial-of-service vulnerability exists in Ser
There is an Integer Underflow (Wrap or Wraparound) Vulnerability in Huawei Smartphone.Successful exploitation of this vu
Integer Underflow in Zephyr in IEEE 802154 Fragment Reassembly Header Removal. Zephyr versions >= >=2.4.0 contain Intege
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R
NVIDIA Linux kernel distributions contain a vulnerability in FuSa Capture (VI/ISP), where integer underflow due to lack
PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto
Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial o
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long inte
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are
Microsoft Office Information Disclosure Vulnerability
TensorFlow is an open source platform for machine learning. In affected versions the Keras pooling layers can trigger a
Integer Underflow vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT
While parsing Service Descriptor Extended Attribute received as part of SDF frame, there is a possibility that incorrect
An issue was discovered on Samsung mobile devices with O(8.x) (Qualcomm chipsets) software. There is an integer underflo
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is an integer underflo
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can
u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute'
u'Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info' in Snapdrago
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4.
An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calli
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2
Possible Integer underflow in WLAN function due to lack of check of data received from user side in Snapdragon Auto, Sna
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory,
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in th
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may
Out of Bound issue in DSP services while processing received arguments due to improper validation of length received as
In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by
Frequently Asked Questions
What is CWE-191?
CWE-191 (CWE-191) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-191?
There are 621 CVE records associated with CWE-191 in our database. Of these, 65 are critical severity, 283 are high severity, and 153 are medium severity.
How can I protect against CWE-191 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-191 using AI-powered security agents.
Detect CWE-191 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-191 vulnerabilities across your infrastructure.
Get Started