Skip to main content

CWE archive

CWE-191 CVEs

Programmatic archive

493 CVEs tagged with CWE-19157 Critical, 256 High, 162 Medium, 18 Low, 0 Unrated.

CVE-2018-21065

Published Apr 8, 2020

An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is an integer underflow in eCryptFS because of a missing size check. The Samsung…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-20590

Published Mar 24, 2020

An issue was discovered on Samsung mobile devices with O(8.x) (Qualcomm chipsets) software. There is an integer underflow in the Secure Storage Trustlet. The Samsung ID is SVE-201…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-9626

Published Jan 24, 2020

Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to cause a denial of service o…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16535

Published Dec 30, 2019

In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-5144

Published Dec 12, 2019

An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Software SDK 7.10.2. A specially crafted jp2 file can cause a he…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5099

Published Nov 6, 2019

An exploitable integer underflow vulnerability exists in the CMP-parsing functionality of LEADTOOLS 20. A specially crafted CMP image file can cause an integer underflow, potentia…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-2187

Published Oct 11, 2019

In nfc_ncif_decode_rf_params of nfc_ncif.cc, there is a possible out of bounds read due to an integer underflow. This could lead to local information disclosure with no additional…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12678

Published Oct 2, 2019

A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software co…

CVSS 7.5 · High

CVE-2019-10054

Published Aug 28, 2019

An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.data. It causes an invalid memory access and the program cras…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20989

Published Aug 26, 2019

An issue was discovered in the untrusted crate before 0.6.2 for Rust. Error handling can trigger an integer underflow and panic.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13104

Published Aug 6, 2019

In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafte…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-14523

Published Aug 2, 2019

An issue was discovered in Schism Tracker through 20190722. There is an integer underflow via a large plen in fmt_okt_load_song in the Amiga Oktalyzer parser in fmt/okt.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14199

Published Jul 31, 2019

An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an *udp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14192

Published Jul 31, 2019

An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 401-425 of 493 CVEsPage 17 of 20