VulnSea

CWE-191

CVEs classified under CWE-191, newest first.

102 CVEsRSS

CVE-2026-43628High· 7.8
1mo ago

llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry…

llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request with dry…

▾ Twilightggml · llama.cppEPSS 0.23%via NVD
CVE-2026-71202High· 7.5
1mo ago

The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only clamps the offset_x/offset_y parameters against 0, never against the source width/height.

The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only clamps the offset_x/offset_y parameters against 0, never against the source width/height.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-67298High· 7.5
1mo ago

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c)

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PD…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.67%via NVD
CVE-2026-54345Medium
2mo ago

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

▾ Sunlitgopacket · github.com/gopacket/gopacketEPSS 0.79%via OSV
CVE-2026-44251Medium· 6.5
2mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to cras…

▾ Sunlitwazuh · wazuhEPSS 0.44%via NVD
CVE-2026-54982High· 8.8
2mo ago

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.53%via CVEORG
CVE-2026-55011High· 7.8
2mo ago

Microsoft Defender Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft Malware Protection EngineEPSS 0.47%via CVEORG
CVE-2026-49790High· 7.3
2mo ago

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.36%via CVEORG
CVE-2026-49181High· 7.5
2mo ago

Windows DHCP Client Elevation of Privilege Vulnerability

Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.2%via CVEORG
CVE-2026-50308High· 7.8
2mo ago

Windows NTFS Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-50300Medium· 5.5
2mo ago

Windows DWM Core Library Information Disclosure Vulnerability

Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-50388High· 7.8
2mo ago

Windows NTFS Remote Code Execution Vulnerability

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-50498High· 7.8
2mo ago

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.36%via CVEORG
CVE-2026-55039High· 7.8
2mo ago

Microsoft Excel Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-58016High· 7.5
2mo ago

A flaw was found in GLib

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other ele…

▾ Twilightgnome · glibEPSS 0.99%via NVD
CVE-2026-53150Medium· 5.5
3mo ago

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Reject zero-length property entries in validator tb_property_entry_valid() accepts entries with length == 0 for DIRECTORY, DATA, and TEXT types

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Reject zero-length property entries in validator tb_property_entry_valid() accepts entries with length == 0 for DIRECTORY, DATA, and TEXT types. A zero-l…

▾ Sunlitlinux · linux_kernelEPSS 0.12%via NVD
CVE-2026-53178High· 8.1
3mo ago

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction Add guards to ensure ie_length is large enough before subtracting fixed IE offsets to prev…

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction Add guards to ensure ie_length is large enough before subtracting fixed IE offsets to prev…

▾ Twilightlinux · linux_kernelEPSS 0.22%via NVD
CVE-2026-53176Critical· 9.8⚖ disputed
3mo ago

In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload length…

In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload length…

▾ Midnightlinux · linux_kernelEPSS 0.76%via NVD
CVE-2026-53130High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START omfs_fill_super() rejects oversized s_sys_blocksize values (> PAGE_SIZE), but it does not reject values sma…

In the Linux kernel, the following vulnerability has been resolved: fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START omfs_fill_super() rejects oversized s_sys_blocksize values (> PAGE_SIZE), but it does not reject values sma…

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2026-30803Critical· 9.1
3mo ago

Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers

Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers. This issue affects Connext Micro: from 4.0.0 before 4.3.0.

▾ Midnightrti · connext_microEPSS 0.51%via NVD
CVE-2026-54413High· 8.2
3mo ago

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potential…

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potential…

▾ TwilightEPSS 0.72%via NVD
CVE-2026-54412High· 8.2
3mo ago

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - …

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - …

▾ TwilightEPSS 0.72%via NVD
CVE-2026-45469High· 7.8
3mo ago

Microsoft Excel Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-45463High· 8.4
3mo ago

Microsoft Office Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.36%via CVEORG
CVE-2026-42981High· 8.1
3mo ago

Windows Performance Monitor Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 11 version 23H2EPSS 0.71%via CVEORG
CVE-2026-42980High· 7.8PoC
3mo ago

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-25104High· 7.8
4mo ago

A heap-based buffer overflow vulnerability exists in the LXF parsing functionality of MediaInfoLib (version(s): 26.01)

A heap-based buffer overflow vulnerability exists in the LXF parsing functionality of MediaInfoLib (version(s): 26.01). A specially crafted .lxf file can lead to arbitrary code execution. An attacker can provide a malicious file to trigg…

▾ Twilightmediaarea · mediainfolibEPSS 0.24%via NVD
CVE-2026-34667Medium· 6.2
4mo ago

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulne…

▾ Sunlitadobe · c2paEPSS 0.26%via NVD
CVE-2026-33845High· 7.5
5mo ago

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may…

▾ Twilightgnu · gnutlsEPSS 0.89%via NVD
CVE-2026-40356Medium· 5.9
5mo ago

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticat…

▾ Sunlitmit · kerberos_5EPSS 0.78%via NVD
CWE-191 vulnerabilities (CVEs) — page 3 · VulnSea