Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-191'

View all threats tagged with 'cwe-191'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-191

Threats Tagged 'cwe-191'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-57918: CWE-191 Integer Underflow (Wrap or Wraparound) in sahlberg libnfsCVE-2026-57918
0

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.

Join the discussion
CVE-2026-30803: CWE-191 Integer Underflow (Wrap or Wraparound) in RTI Connext MicroCVE-2026-30803
0

Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before 4.3.0.

Join the discussion
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security UpdateCVE-2026-11850
0

A security update for Red Hat Hardened Images RPMs addresses a vulnerability identified as CVE-2026-11850 affecting multiple krb5 packages. The vulnerability is related to an integer overflow (CWE-191) and impacts confidentiality and availability. The update includes patched versions of krb5 components for aarch64 and x86_64 architectures. No known exploits are reported in the wild. The advisory does not explicitly state fixed versions or detailed exploitation methods.

Join the discussion
CVE-2026-54413: CWE-191 Integer Underflow (Wrap or Wraparound) in driftregion iso14229CVE-2026-54413
0

CVE-2026-54413 is an integer underflow vulnerability in the driftregion iso14229 library version 0.9.0 and earlier. It occurs in the Handle_0x27_SecurityAccess() function, which improperly handles the length of a SecurityAccess request, allowing a remote unauthenticated attacker to cause a crash or potentially read memory beyond the receive buffer. This vulnerability affects UDS servers deployed on automotive ECUs, industrial controllers, and IoT devices using this library. The flaw arises because the function does not validate that the received message length is at least two bytes before accessing the buffer, leading to an underflow and out-of-bounds read. The vulnerability has a high severity score of 7.8 and is exploitable remotely without authentication.

Join the discussion
CVE-2026-54412: CWE-125 Out-of-bounds Read in LiamBindle MQTT-CCVE-2026-54412
0

LiamBindle MQTT-C versions up to 1.1.6 contain a heap-based out-of-bounds read and integer underflow vulnerability in the mqtt_unpack_publish_response() function. This flaw allows a remote unauthenticated attacker controlling an MQTT broker or able to inject MQTT traffic into an unencrypted session to crash a subscribed MQTT-C client and potentially disclose adjacent heap memory by sending a crafted PUBLISH packet. The vulnerability arises from improper validation of the topic_name_size field relative to the remaining packet length, leading to an out-of-bounds read and a large memmove() operation that crashes the process.

Join the discussion
CVE-2026-47222: CWE-125: Out-of-bounds Read in M2Team NanaZipCVE-2026-47222
0

NanaZip versions from 3.0.1000.0 up to but not including 6.0.1698.0 contain a heap out-of-bounds read vulnerability in the Android Verified Boot (AVB) vbmeta image parser. This is caused by an unsigned integer underflow in a bounds check, allowing a crafted .avb or .img file to trigger a read beyond the allocated buffer, leading to a deterministic crash (denial of service). The issue has been patched in version 6.0.1698.0 and later.

Join the discussion
CVE-2026-42542: CWE-191: Integer Underflow (Wrap or Wraparound) in taosdata TDengineCVE-2026-42542
0

TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the issue.

Join the discussion
CVE-2026-45469: CWE-191: Integer Underflow (Wrap or Wraparound) in Microsoft Microsoft 365 Apps for EnterpriseCVE-2026-45469
0

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Join the discussion
CVE-2026-45463: CWE-191: Integer Underflow (Wrap or Wraparound) in Microsoft Microsoft 365 Apps for EnterpriseCVE-2026-45463
0

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Join the discussion
CVE-2026-42981: CWE-191: Integer Underflow (Wrap or Wraparound) in Microsoft Windows 11 version 23H2CVE-2026-42981
0

Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Tag: cwe-191
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses