VulnSea

CWE-191

CVEs classified under CWE-191, newest first.

91 CVEsRSS

CVE-2026-94090Medium· 6.3
2d ago

A security flaw has been discovered in JusticeRage Manalyze 1.0.0

A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the component PE Parser. The manipulation of the argument misc.Length results in intege…

SunlitJusticeRage · ManalyzeEPSS 0.31%via NVD
CVE-2026-61720Medium· 6.2
4d ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one record. A cr…

SunlitFluidSynth · fluidsynthEPSS 0.14%via NVD
CVE-2026-93599High· 7.5PoC
4d ago

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (ze…

Midnightrustls · webpkiEPSS 0.35%via NVD
CVE-2026-93395Medium· 5.3
5d ago

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but doe…

SunlitMongoDB Inc. · C DriverEPSS 0.24%via NVD
CVE-2026-44235Medium· 6.5PoC
5d ago

rabbitmq-c is a C-language AMQP client library for RabbitMQ

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabb…

Twilightalanxz · rabbitmq-cEPSS 0.35%via NVD
CVE-2026-91103Critical· 9.8⚖ disputed
6d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.29%via NVD
CVE-2026-89028High· 7.5
6d ago

MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX ha…

MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX ha…

TwilightMikroTik · RouterOSEPSS 0.56%via NVD
CVE-2026-91948High· 7.5PoC
1w ago

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that caus…

MidnightFreeRDP · FreeRDPEPSS 0.65%via NVD
CVE-2026-90996Medium· 4.0
1w ago

A flaw was found in sssd

A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS respon…

SunlitRed Hat · sssdEPSS 0.11%via NVD
CVE-2026-89476High· 7.0
1w ago

kernel: sctp: fix stream->outcnt underflow on duplicate RECONF responses (CVE-2026-89476)

A flaw was found in the Linux kernel's Stream Control Transmission Protocol (SCTP) implementation. A remote attacker could exploit this by sending specially crafted duplicate RECONF responses. This action can cause an underflow in the `str…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.69%via CSAF
CVE-2026-89551High· 7.0⚖ disputed
1w ago

kernel: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow (CVE-2026-89551)

A flaw was found in the Linux kernel's SUNRPC subsystem, specifically within the `xdr_buf_trim()` function. This vulnerability occurs when `xdr_buf_trim()` attempts to reduce the size of an XDR buffer. If the buffer's length is smaller tha…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.52%via CSAF
CVE-2026-89533High· 7.0⚖ disputed
1w ago

kernel: svcrdma: Fix offset arithmetic in read_chunk_range (CVE-2026-89533)

A flaw was found in the `svcrdma` component of the Linux kernel. Incorrect offset arithmetic in the `svc_rdma_read_chunk_range()` function can lead to a `u32` underflow. This underflow can cause the system to attempt to allocate a large am…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.51%via CSAF
CVE-2026-89606High· 7.0
1w ago

kernel: ecryptfs: reject too-small tag 70 packets (CVE-2026-89606)

A flaw was found in ecryptfs, a component of the Linux kernel. This vulnerability allows a remote attacker to send a specially crafted tag 70 packet with a body smaller than expected. This can lead to an integer underflow during size calcu…

TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.14%via CSAF
CVE-2026-13326Medium· 6.9
1w ago

An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

Sunlitqt · qtEPSS 0.15%via NVD
CVE-2026-81977Medium· 5.5
2w ago

Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory

Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of thi…

Sunlitadobe · acrobatEPSS 0.17%via NVD
CVE-2026-66307High· 7.5
2w ago

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

Twilightmicrosoft · skype_for_business_serverEPSS 0.63%via NVD
CVE-2026-78453Medium· 6.5
2w ago

Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.

Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.

Sunlitmicrosoft · windows_10_1607EPSS 0.92%via NVD
CVE-2026-77488Medium· 5.5
2w ago

Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.

Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · sql_server_2017EPSS 0.30%via NVD
CVE-2026-72947Medium· 6.4
2w ago

Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.

Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-71352High· 8.8
2w ago

Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.

Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.66%via NVD
CVE-2026-69859High· 7.0
2w ago

Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.19%via NVD
CVE-2026-69824Critical· 9.8
2w ago

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.

MidnightMicrosoft · Windows 10 Version 1607EPSS 1.00%via NVD
CVE-2026-69687High· 7.8
2w ago

Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.31%via NVD
CVE-2026-69421High· 7.8
2w ago

Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.31%via NVD
CVE-2026-69303Medium· 5.5
2w ago

Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via NVD
CVE-2026-69276Critical· 9.8
2w ago

Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.

Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.

MidnightMicrosoft · Windows 10 Version 1607EPSS 0.93%via NVD
CVE-2026-69269High· 7.8
2w ago

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.32%via NVD
CVE-2026-68827High· 8.0
2w ago

Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.

Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · windows_10_1607EPSS 0.40%via NVD
CVE-2026-66767High· 7.7
2w ago

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session …

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session …

TwilightSAP_SE · SAP NetWeaver Application Server for ABAP and ABAP PlatformEPSS 0.26%via NVD
CVE-2026-18355High· 7.5
2w ago

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base)

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, …

TwilightRed Hat · redhat-ds:11EPSS 0.84%via NVD
CWE-191 vulnerabilities (CVEs) · VulnSea