VulnSea

CWE-191

CVEs classified under CWE-191, newest first.

102 CVEsRSS

CVE-2026-31617Medium· 5.5
5mo ago

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() The block_len read from the host-supplied NTB header is checked against ntb_max but has no lower bou…

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() The block_len read from the host-supplied NTB header is checked against ntb_max but has no lower bou…

▾ Sunlitlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-5720Critical· 9.1
5mo ago

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attacker…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-27907High· 7.8
5mo ago

Windows Storage Spaces Controller Elevation of Privilege Vulnerability

Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 22H3EPSS 0.33%via CVEORG
CVE-2026-32149High· 7.3
5mo ago

Windows Hyper-V Remote Code Execution Vulnerability

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.43%via CVEORG
CVE-2026-27297High· 7.8
5mo ago

Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires us…

▾ Twilightadobe · framemakerEPSS 0.29%via NVD
CVE-2026-27296High· 7.8
5mo ago

Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires us…

▾ Twilightadobe · framemakerEPSS 0.29%via NVD
CVE-2026-34165Medium· 5.0
6mo ago

go-git is an extensible git implementation library written in pure Go

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, pot…

▾ Sunlitgo-git_project · go-gitEPSS 0.15%via NVD
CVE-2025-67269High· 7.5
8mo ago

An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e563160ebb67199da7`

An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e563160ebb67199da7`. When parsing a NAVCOM packet, the payload length is calculated using …

▾ Twilightgpsd_project · gpsdEPSS 0.55%via NVD
CVE-2025-4948High· 7.5
1y ago

A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications

A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially cr…

▾ TwilightEPSS 0.78%via NVD
CVE-2024-30070High· 7.5
2y ago

DHCP Server Service Denial of Service Vulnerability

DHCP Server Service Denial of Service Vulnerability

▾ Twilightmicrosoft · windows_server_2012EPSS 2.3%via NVD
CVE-2024-0565Medium· 6.8
2y ago

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denia…

▾ Sunlitnetapp · ontap_toolsEPSS 2.0%via NVD
CVE-2019-12678High· 7.5
6y ago

A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a d…

A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a d…

▾ Twilightcisco · adaptive_security_applianceEPSS 1.8%via NVD
CWE-191 vulnerabilities (CVEs) — page 4 · VulnSea