VulnSea

CWE-191

CVEs classified under CWE-191, newest first.

102 CVEsRSS

CVE-2026-69269High· 7.8
2w ago

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.34%via NVD
CVE-2026-68827High· 8.0
2w ago

Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.

Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.77%via NVD
CVE-2026-66767High· 7.7
2w ago

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session …

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session …

▾ TwilightSAP_SE · SAP NetWeaver Application Server for ABAP and ABAP PlatformEPSS 0.43%via NVD
CVE-2026-18355High· 7.5
2w ago

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base)

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, …

▾ TwilightRed Hat · redhat-ds:11EPSS 0.84%via NVD
CVE-2026-18341Medium· 6.3
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow.

▾ Sunlitibm · iEPSS 0.25%via NVD
CVE-2026-85436High· 7.5
3w ago

MOOS essential-moos through 10.0.1 contains a buffer overflow vulnerability in CMOOSUDPLink::ReadPktFromArray() that allows remote attackers to corrupt heap memory by sending UDP datagrams with negative declared lengths

MOOS essential-moos through 10.0.1 contains a buffer overflow vulnerability in CMOOSUDPLink::ReadPktFromArray() that allows remote attackers to corrupt heap memory by sending UDP datagrams with negative declared lengths. Attackers can se…

▾ TwilightEPSS 2.1%via NVD
CVE-2026-82480High· 7.4
4w ago

A security flaw has been discovered in NASA cFS up to 7.0.1

A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulat…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-19318None
1mo ago

A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

▾ SunlitEPSS 0.47%via NVD
CVE-2026-54754Critical· 9.6
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPer…

▾ Midnightklever-io · github.com/klever-io/klever-goEPSS 0.43%via NVD
GHSA-2vh6-hw4j-32wwMedium· 6.5
1mo ago

gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)

gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)

▾ Sunlitgix-packetline · gix-packetlinevia GHSA
CVE-2026-18916High· 7.5
1mo ago

Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query

Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.

▾ Twilightnlnetlabs · nsdEPSS 0.28%via NVD
CVE-2026-62289Medium· 4.3
1mo ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_hand…

▾ Sunlitstrukturag · libheifEPSS 0.40%via NVD
CVE-2026-45698High· 7.5
1mo ago

Netatalk is a Free and Open Source file server suite for Unix-like operating systems

Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the deletedir() function of Netatalk's afpd daemon due to an integer underflo…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-49282Medium· 5.1
1mo ago

Capstone is a disassembly framework

Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before index…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-45699High· 7.5
1mo ago

Netatalk is a Free and Open Source file server suite for Unix-like operating systems

Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer underflow…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-16241Low· 3.8
1mo ago

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory regio…

▾ Sunlitpostgresql · postgresqlEPSS 0.20%via NVD
CVE-2026-73433Medium· 6.6
1mo ago

A flaw was found in GStreamer gst-plugins-good (avidemux)

A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying suffici…

▾ Sunlitgstreamer · gstreamerEPSS 0.15%via NVD
CVE-2026-62745Medium· 6.5
1mo ago

Windows DHCP Server Information Disclosure Vulnerability

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ SunlitMicrosoft · Windows Server 2012EPSS 0.54%via CVEORG
CVE-2026-62742Medium· 6.5
1mo ago

Windows DHCP Server Information Disclosure Vulnerability

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ SunlitMicrosoft · Windows Server 2012EPSS 0.54%via CVEORG
CVE-2026-63515High· 7.8
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-62720Medium· 6.5
1mo ago

Windows DHCP Server Information Disclosure Vulnerability

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ SunlitMicrosoft · Windows Server 2012EPSS 0.54%via CVEORG
CVE-2026-62814Medium· 6.5
1mo ago

Windows DHCP Server Information Disclosure Vulnerability

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ SunlitMicrosoft · Windows Server 2012EPSS 0.54%via CVEORG
CVE-2026-62741High· 7.8
1mo ago

Windows HTTP.sys Elevation of Privilege Vulnerability

Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-64909High· 7.8
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-18687High· 7.1
1mo ago

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privil…

▾ Twilightmongodb · mongodbEPSS 0.23%via NVD
CVE-2026-62718Medium· 6.5
1mo ago

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.54%via NVD
CVE-2026-62716Medium· 6.5
1mo ago

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.54%via NVD
CVE-2026-62715Medium· 6.5
1mo ago

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.54%via NVD
CVE-2026-62714Medium· 6.5
1mo ago

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.54%via NVD
CVE-2026-62696High· 7.8
1mo ago

Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CWE-191 vulnerabilities (CVEs) — page 2 · VulnSea