Skip to main content

Threats Tagged 'cwe-191'

View all threats tagged with 'cwe-191'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-191

Threats Tagged 'cwe-191'

Click on any threat for detailed analysis and mitigation recommendations

0

CVE-2026-13326 is an out-of-bounds read vulnerability in Qt NFC's language code length parsing. This flaw allows a physically proximate attacker to cause a denial of service or limited memory disclosure by using a specially crafted NFC tag. The vulnerability affects Qt versions from 5.2.0 up to but not including 6.8.9, and from 6.9.0 up to but not including 6.11.2. It has a CVSS 4.0 score of 6.9, indicating a critical severity level. No explicit patch links are provided in the data, and no known exploits are reported in the wild.

Join the discussion

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime. An attacker with root access to a partition can send a specially crafted request to the partition firmware runtime, causing it to crash with possible memory corruption.

Join the discussion

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata section base, making subtraction produce a negative logical index. The vulnerability is triggered by parsing Swift type and class metadata from a crafted Mach-O file. The derived index was used to read four bytes immediately before the allocated field-metadata buffer. This can cause incorrect metadata processing or process termination; no attacker-observable memory disclosure has been demonstrated. This issue is fixed in version 6.2.0.

Join the discussion

CVE-2026-93395 is an integer underflow vulnerability in the bson_new_from_buffer() function of the MongoDB C Driver. The function fails to validate that the BSON document length is at least 5 bytes, allowing a zero-length prefix to cause an integer wraparound. This leads to a heap out-of-bounds read and a process crash, resulting in a denial of service. The vulnerability affects versions from 2.0.0 up to but not including 2.3.1. No known exploits are reported in the wild. The CVSS 4.0 score is 6.9, indicating a medium severity.

Join the discussion

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabbitmq/amqp_connection.c. The parser subtracts HEADER_SIZE, fixed per-frame fields, and FOOTER_SIZE from state->target_size without first checking the minimum frame length. The wrapped encoded.len value is passed through amqp_decode_properties() to amqp_decode_table_internal(), where it defeats bounds checks and causes an out-of-bounds read and process crash. An on-path attacker can also trigger the issue when AMQP traffic is not protected by TLS with certificate validation. The demonstrated impact is denial of service, with no reliable memory disclosure or code execution shown. This issue is fixed in version 0.16.0.

Join the discussion

CVE-2026-91103 is an integer underflow vulnerability (CWE-191) in HP Linux Imaging and Printing Software (HPLIP) versions before 3.26.6. HP has identified and fixed multiple vulnerabilities in HPLIP that could allow remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. The CVSS 4.0 base score is 5.1, indicating a medium severity level.

Join the discussion

Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Join the discussion

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

Join the discussion

Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.

Join the discussion

Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.

Join the discussion

Showing 1 to 10 of 183 results

Filters:Tag: cwe-191
Page 1 of 19
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses