CVE & CISA-KEV Catalog
Want to know which of these are on your machines? Scan your endpoints with the free CVE scanner, 200 endpoints free.
| Severity | Description | ||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-107794 | Unscored | - | - | - | -No fix available yet | 2026-10-10 | ExtUtils::Typemaps::STL::List versions before 1.07 for Perl allocate a 32 GiB array on an empty list. The OUTPUT typemaps call av_extend( av, len-1 ). On an empty list, this undeflows, and av_extend will allocate an array with 2^32 slots, leading to memory exhaustion. Note that a similar issue was fixed in ExtUtils::Typemaps::STL::Vector version 1.05. |
| CVE-2013-10076 | Unscored | - | - | - | -No fix available yet | 2026-10-10 | ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl allocate a 32 GiB array on an empty list. The OUTPUT typemaps call av_extend( av, len-1 ). On an empty list, this undeflows, and av_extend will allocate an array with 2^32 slots, leading to memory exhaustion. |
| CVE-2026-103636 | Unscored | - | - | - | -No fix available yet | 2026-10-10 | Out-of-bounds read in the VarOpt union deserialization of Apache DataSketches C++ (repo: datasketches-cpp). var_opt_union::deserialize() read the 32-byte preamble of a non-empty union after checking that only 8 bytes were available, so a truncated serialized union could cause a read of up to 24 bytes past the end of the input. For such inputs, the size remaining for the embedded sketch was also computed by an unsigned subtraction that could wrap around, so the embedded sketch's own size checks no longer limited reads to the input. The bytes read can become part of the deserialized union's state. This can cause a crash (denial of service) and could expose adjacent memory contents. This issue affects Apache DataSketches C++: from 2.0.0-incubating before 5.3.0. Only applications that deseri |
| CVE-2026-107836 | High | 7.1 v4 | - | - | -No fix available yet | 2026-10-09 | RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, the nanoCoAP client function nanocoap_sock_get_slice() in sys/net/application_layer/nanocoap/sock.c accepts a Block2 response when _block_cb() sees the expected block number without also verifying that the server-controlled szx and derived offset match the requested block geometry. A malicious CoAP server can return the expected block number with a larger block size, causing the derived offset to exceed the client slice offset and making ctx->offset - offset underflow in _2buf_slice(). The resulting buffer-relative calculation can read before the payload buffer and crash the client, causing denial of service and potentially exposing adjacent me |
| CVE-2026-106437 | Medium | 6.2 v3 | 0.1% | - | Fix available | 2026-10-08 | The BSON buffer-reservation API in the MongoDB C Driver can record a length smaller than the five-byte BSON minimum. Later append or comparison operations can underflow unsigned length calculations and read or write outside the document buffer. An actor who can influence the length supplied by an embedding application can cause the application to terminate or read or corrupt adjacent process memory. Reaching this issue requires the application to pass an undersized value to bson_reserve_buffer and then perform an affected operation. |
| CVE-2026-106429 | Medium | 6.5 v3 | 0.3% | - | Fix available | 2026-10-08 | An integer underflow in the KMS endpoint-parsing logic of MongoDB libmongocrypt can cause an allocation failure that terminates the application process. This can occur when an authenticated user modifies a key document in the key vault collection, or when an application accepts a KMS endpoint containing a colon after its path or query during key creation. The issue does not access memory outside its allocated bounds. |
| CVE-2026-107635 | Medium | 5.5 v3 | 0.1% | - | -No fix available yet | 2026-10-08 | Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum_size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker. |
| CVE-2026-107614 | Medium | 6.1 v3 | 0.1% | - | -No fix available yet | 2026-10-08 | An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place. |
| CVE-2026-19186 | High | 8.1 v3 | 0.2% | - | -No fix available yet | 2026-10-07 | ieee802154_decipher_data_frame() in subsys/net/l2/ieee802154/ieee802154_frame.c computed payload_len = net_pkt_get_len(pkt) - ll_hdr_len - authtag_len without first checking that the received frame is at least ll_hdr_len + authtag_len bytes long. All three variables are uint8_t, so a frame whose payload is shorter than the configured authentication tag makes the subtraction wrap around to a large value (up to 255). The wrapped length is passed unchanged to ieee802154_decrypt_auth() and on to the CCM operation as cipher_pkt.in_len/out_buf_max, with apkt->tag pointing at frame + ll_hdr_len + payload_len. Because the receive buffer is allocated to the exact length of the frame received from the radio driver, the crypto layer then reads several hundred bytes past the end of the packet buffer |
| CVE-2026-78453 | High | 6.5 v3 | 0.9% | - | Fix available | 2026-10-07 | Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-83742 | Medium | 5.3 v4 | 0.3% | - | -No fix available yet | 2026-10-07 | Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. wolfSSH_RealPath() in src/ssh.c appends each path component with a remaining-size bound (outSz - curSz) rather than the full destination size, so once the accumulated path reaches half the output buffer the size_t computation n - strlen(s1) - 1 wraps to near SIZE_MAX. The strncat() call is then effectively unbounded and copies the whole component; when that component exactly fills the remainder of the buffer, its terminating null is written one byte past the end. The caller's own length check keeps the copied data inside the bu |
| CVE-2026-86537 | High | 8.7 v4 | 0.6% | - | -No fix available yet | 2026-10-07 | Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
| CVE-2026-102168 | Medium | 6.5 v3 | 0.3% | - | -No fix available yet | 2026-10-06 | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is not possible. |
| CVE-2026-62741 | High | 7.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
| CVE-2026-82459 | Medium | 8.2 v4 | 0.4% | - | -No fix available yet | 2026-10-03 | Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |
| CVE-2026-84411 | Critical | 9.8 v3 | 0.9% | - | -No fix available yet | 2026-10-02 | The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request. |
| CVE-2026-47585 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2026-09-30 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
| CVE-2026-47540 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2026-09-30 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
| CVE-2026-86133 | High | 7.5 v3 | 0.3% | - | Fix available | 2026-09-30 | An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service. |
| CVE-2026-86132 | High | 7.5 v3 | 0.4% | - | Fix available | 2026-09-30 | An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite. |
| CVE-2026-102714 | High | 7.1 v4 | 0.2% | - | -No fix available yet | 2026-09-29 | `_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes. Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls. **Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), |
| CVE-2026-93599 | High | 7.5 v3 | 0.3% | - | Fix available | 2026-09-29 | rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (zero padding bits and no data bytes), so raw_bits.len() - 1 underflows on the empty slice and the subsequent index operation panics (subtract-with-overflow in debug, index-out-of-bounds in release). The condition is reachable through the public API BorrowedCertRevocationList::from_der() when a CRL contains an issuingDistributionPoint extension with such an onlySomeReasons value. Exploitation requires an application that explicitly opts in to CRL revocation checking by passing RevocationOptions to verify_for_usage() and that parses CRL bytes obtained from a so |
| CVE-2026-18747 | Medium | 6.8 v3 | 0.1% | - | -No fix available yet | 2026-09-29 | The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len -= 2U; in mcumgr_serial_process_frag() (subsys/mgmt/mcumgr/transport/src/serial_util.c). mcumgr_serial_extract_len() accepted any declared length, including 0 and 1, and a packet declaring length 0 passes the checksum test for free because crc16_itu_t() over zero bytes returns the zero seed. Since net_buf::len is a uint16_t, the subtraction underflows and the buffer is handed to SMP claiming roughly 65 KB of payload while its data area is only CONFIG_MCUMGR_TRANSPORT_NETBUF_SIZE bytes (default 384). The trigger is a single unauthenticated 7-byte line on the management console — the 0x06 0x09 packet marker |
| CVE-2026-88377 | Medium | 6.2 v3 | 0.1% | - | -No fix available yet | 2026-09-24 | Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE can cause AP4_AvccAtom::Create() or AP4_HvccAtom::Create() to underflow the payload-size calculation. The resulting oversized buffer operation can cause invalid or NULL pointers to be passed to the AP4_DataBuffer copy path, resulting in application termination and denial of service. |
| CVE-2026-88376 | High | 7.5 v3 | 0.4% | - | -No fix available yet | 2026-09-24 | Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC atom with a declared size smaller than the atom header size can cause the payload-size calculation to wrap to a large unsigned value. The resulting invalid buffer allocation and copy operations can cause application termination, leading to denial of service. |
| CVE-2026-17504 | Medium | 5.1 v3 | 0.1% | - | Fix available | 2026-09-24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime. An attacker with root access to a partition can send a specially crafted request to the partition firmware runtime, causing it to crash with possible memory corruption. |
| CVE-2026-95958 | Low | 3.3 v3 | 0.1% | - | -No fix available yet | 2026-09-23 | A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing a manipulation of the argument BlockSize results in integer underflow. The attack requires a local approach. The patch is named c372b6bbca9d8c63812be50596fefa4a79c65fd0. It is recommended to apply a patch to fix this issue. |
| CVE-2026-81881 | Low | 3.3 v3 | 0.1% | - | Fix available | 2026-09-22 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata section base, making subtraction produce a negative logical index. The vulnerability is triggered by parsing Swift type and class metadata from a crafted Mach-O file. The derived index was used to read four bytes immediately before the allocated field-metadata buffer. This can cause incorrect metadata processing or process termination; no attacker-observable memory disclosure has been demonstrated. This issue is fixed in version 6.2.0. |
| CVE-2026-55039 | High | 7.8 v3 | 0.5% | - | Fix available | 2026-09-21 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2026-94090 | Medium | 6.3 v3 | 0.4% | - | -No fix available yet | 2026-09-20 | A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the component PE Parser. The manipulation of the argument misc.Length results in integer underflow. The attack may be performed from remote. The patch is identified as 3e299685759f4f767088871de58c5d07f98ee382. A patch should be applied to remediate this issue. |
| CVE-2026-61720 | Medium | 6.2 v3 | 0.2% | - | Fix available | 2026-09-18 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one record. A crafted SF2 file containing a zero-sized DMOD chunk makes the unsigned subtraction wrap to UINT_MAX, and the parser then attempts billions of SFMod allocations. This exhausts process memory and causes denial of service. No workaround is available. This issue is fixed in version 2.5.6. |
| CVE-2026-93395 | Medium | 5.3 v3 | 0.4% | - | Fix available | 2026-09-17 | A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but does not verify that the value is at least 5 (the minimum valid BSON document size) before using it in an array index calculation. When the length field is zero, the expression used to check the document's null terminator wraps to UINT32_MAX, causing a heap out-of-bounds read that crashes the process. An unauthorized party who can supply crafted BSON input to an application using this API can cause a denial of service. |
| CVE-2026-44235 | Medium | 6.5 v3 | 0.3% | - | Fix available | 2026-09-17 | rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabbitmq/amqp_connection.c. The parser subtracts HEADER_SIZE, fixed per-frame fields, and FOOTER_SIZE from state->target_size without first checking the minimum frame length. The wrapped encoded.len value is passed through amqp_decode_properties() to amqp_decode_table_internal(), where it defeats bounds checks and causes an out-of-bounds read and process crash. An on-path attacker can also trigger the issue when AMQP traffic is not protected by TLS with certificate validation. The demonstrated impact is denial of service, with no reliable memory disclosure or c |
| CVE-2026-91103 | Critical | 9.8 v3 | 1.0% | - | Fix available | 2026-09-16 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. |
| CVE-2026-89028 | High | 7.5 v3 | 0.6% | - | -No fix available yet | 2026-09-16 | MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that triggers an integer underflow, causing the resulting value to be used as the copy length in a memory copy operation into a smaller heap buffer, corrupting adjacent heap memory. |
| CVE-2026-91948 | High | 7.5 v3 | 0.6% | - | -No fix available yet | 2026-09-15 | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution. |
| CVE-2026-90996 | Medium | 4.0 v3 | 0.1% | - | -No fix available yet | 2026-09-14 | A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder. |
| CVE-2026-13326 | Medium | 6.9 v4 | 0.2% | - | -No fix available yet | 2026-09-11 | An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag. |
| CVE-2026-81977 | Medium | 5.5 v3 | 0.3% | - | Fix available | 2026-09-08 | Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
| CVE-2026-77488 | High | 5.5 v3 | 0.4% | - | Fix available | 2026-09-08 | Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally. |
| CVE-2026-72947 | High | 6.4 v3 | 0.3% | - | Fix available | 2026-09-08 | Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-71352 | High | 8.8 v3 | 0.9% | - | Fix available | 2026-09-08 | Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network. |
| CVE-2026-69859 | High | 7.0 v3 | 0.2% | - | Fix available | 2026-09-08 | Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69824 | High | 9.8 v3 | 1.0% | - | Fix available | 2026-09-08 | Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69687 | High | 7.8 v3 | 0.3% | - | Fix available | 2026-09-08 | Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69421 | High | 7.8 v3 | 0.3% | - | Fix available | 2026-09-08 | Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69303 | High | 5.5 v3 | 0.4% | - | Fix available | 2026-09-08 | Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. |
| CVE-2026-69276 | High | 9.8 v3 | 1.0% | - | Fix available | 2026-09-08 | Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69269 | High | 7.8 v3 | 0.3% | - | Fix available | 2026-09-08 | Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. |
| CVE-2026-68827 | High | 8.0 v3 | 0.8% | - | Fix available | 2026-09-08 | Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network. |
- UnscoredCVSS -·EPSS -·No fix yet
ExtUtils::Typemaps::STL::List versions before 1.07 for Perl allocate a 32 GiB array on an empty list. The OUTPUT typemaps call av_extend( av, len-1 ). On an empty list, this undeflows, and av_extend will allocate an array with 2^32 slots, leading to memory exhaustion. Note that a similar issue was fixed in ExtUtils::Typemaps::STL::Vector version 1.05.
Published 2026-10-10
- UnscoredCVSS -·EPSS -·No fix yet
ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl allocate a 32 GiB array on an empty list. The OUTPUT typemaps call av_extend( av, len-1 ). On an empty list, this undeflows, and av_extend will allocate an array with 2^32 slots, leading to memory exhaustion.
Published 2026-10-10
- UnscoredCVSS -·EPSS -·No fix yet
Out-of-bounds read in the VarOpt union deserialization of Apache DataSketches C++ (repo: datasketches-cpp). var_opt_union::deserialize() read the 32-byte preamble of a non-empty union after checking that only 8 bytes were available, so a truncated serialized union could cause a read of up to 24 bytes past the end of the input. For such inputs, the size remaining for the embedded sketch was also computed by an unsigned subtraction that could wrap around, so the embedded sketch's own size checks no longer limited reads to the input. The bytes read can become part of the deserialized union's state. This can cause a crash (denial of service) and could expose adjacent memory contents. This issue affects Apache DataSketches C++: from 2.0.0-incubating before 5.3.0. Only applications that deseri
Published 2026-10-10
- HighCVSS 7.1 v4·EPSS -·No fix yet
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, the nanoCoAP client function nanocoap_sock_get_slice() in sys/net/application_layer/nanocoap/sock.c accepts a Block2 response when _block_cb() sees the expected block number without also verifying that the server-controlled szx and derived offset match the requested block geometry. A malicious CoAP server can return the expected block number with a larger block size, causing the derived offset to exceed the client slice offset and making ctx->offset - offset underflow in _2buf_slice(). The resulting buffer-relative calculation can read before the payload buffer and crash the client, causing denial of service and potentially exposing adjacent me
Published 2026-10-09
- MediumCVSS 6.2 v3·EPSS 0.1%·Fix available
The BSON buffer-reservation API in the MongoDB C Driver can record a length smaller than the five-byte BSON minimum. Later append or comparison operations can underflow unsigned length calculations and read or write outside the document buffer. An actor who can influence the length supplied by an embedding application can cause the application to terminate or read or corrupt adjacent process memory. Reaching this issue requires the application to pass an undersized value to bson_reserve_buffer and then perform an affected operation.
Published 2026-10-08
- MediumCVSS 6.5 v3·EPSS 0.3%·Fix available
An integer underflow in the KMS endpoint-parsing logic of MongoDB libmongocrypt can cause an allocation failure that terminates the application process. This can occur when an authenticated user modifies a key document in the key vault collection, or when an application accepts a KMS endpoint containing a colon after its path or query during key creation. The issue does not access memory outside its allocated bounds.
Published 2026-10-08
- MediumCVSS 5.5 v3·EPSS 0.1%·No fix yet
Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum_size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker.
Published 2026-10-08
- MediumCVSS 6.1 v3·EPSS 0.1%·No fix yet
An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place.
Published 2026-10-08
- HighCVSS 8.1 v3·EPSS 0.2%·No fix yet
ieee802154_decipher_data_frame() in subsys/net/l2/ieee802154/ieee802154_frame.c computed payload_len = net_pkt_get_len(pkt) - ll_hdr_len - authtag_len without first checking that the received frame is at least ll_hdr_len + authtag_len bytes long. All three variables are uint8_t, so a frame whose payload is shorter than the configured authentication tag makes the subtraction wrap around to a large value (up to 255). The wrapped length is passed unchanged to ieee802154_decrypt_auth() and on to the CCM operation as cipher_pkt.in_len/out_buf_max, with apkt->tag pointing at frame + ll_hdr_len + payload_len. Because the receive buffer is allocated to the exact length of the frame received from the radio driver, the crypto layer then reads several hundred bytes past the end of the packet buffer
Published 2026-10-07
- HighCVSS 6.5 v3·EPSS 0.9%·Fix available
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.
Published 2026-10-07
- MediumCVSS 5.3 v4·EPSS 0.3%·No fix yet
Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. wolfSSH_RealPath() in src/ssh.c appends each path component with a remaining-size bound (outSz - curSz) rather than the full destination size, so once the accumulated path reaches half the output buffer the size_t computation n - strlen(s1) - 1 wraps to near SIZE_MAX. The strncat() call is then effectively unbounded and copies the whole component; when that component exactly fills the remainder of the buffer, its terminating null is written one byte past the end. The caller's own length check keeps the copied data inside the bu
Published 2026-10-07
- HighCVSS 8.7 v4·EPSS 0.6%·No fix yet
Uncaught exception, Loop with unreachable exit condition ('infinite loop'), Integer underflow (wrap or wraparound) vulnerability in Apache Thrift D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published 2026-10-07
- MediumCVSS 6.5 v3·EPSS 0.3%·No fix yet
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is not possible.
Published 2026-10-06
- HighCVSS 7.8 v3·EPSS 0.3%·Fix available
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Published 2026-10-06
- MediumCVSS 8.2 v4·EPSS 0.4%·No fix yet
Integer underflow (wrap or wraparound), Out-of-bounds write vulnerability in Apache Thrift C++ 32 bit THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Published 2026-10-03
- CriticalCVSS 9.8 v3·EPSS 0.9%·No fix yet
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
Published 2026-10-02
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published 2026-09-30
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published 2026-09-30
- HighCVSS 7.5 v3·EPSS 0.3%·Fix available
An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service.
Published 2026-09-30
- HighCVSS 7.5 v3·EPSS 0.4%·Fix available
An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.
Published 2026-09-30
- HighCVSS 7.1 v4·EPSS 0.2%·No fix yet
`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes. Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls. **Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`),
Published 2026-09-29
- HighCVSS 7.5 v3·EPSS 0.3%·Fix available
rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (zero padding bits and no data bytes), so raw_bits.len() - 1 underflows on the empty slice and the subsequent index operation panics (subtract-with-overflow in debug, index-out-of-bounds in release). The condition is reachable through the public API BorrowedCertRevocationList::from_der() when a CRL contains an issuingDistributionPoint extension with such an onlySomeReasons value. Exploitation requires an application that explicitly opts in to CRL revocation checking by passing RevocationOptions to verify_for_usage() and that parses CRL bytes obtained from a so
Published 2026-09-29
- MediumCVSS 6.8 v3·EPSS 0.1%·No fix yet
The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len -= 2U; in mcumgr_serial_process_frag() (subsys/mgmt/mcumgr/transport/src/serial_util.c). mcumgr_serial_extract_len() accepted any declared length, including 0 and 1, and a packet declaring length 0 passes the checksum test for free because crc16_itu_t() over zero bytes returns the zero seed. Since net_buf::len is a uint16_t, the subtraction underflows and the buffer is handed to SMP claiming roughly 65 KB of payload while its data area is only CONFIG_MCUMGR_TRANSPORT_NETBUF_SIZE bytes (default 384). The trigger is a single unauthenticated 7-byte line on the management console — the 0x06 0x09 packet marker
Published 2026-09-29
- MediumCVSS 6.2 v3·EPSS 0.1%·No fix yet
Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE can cause AP4_AvccAtom::Create() or AP4_HvccAtom::Create() to underflow the payload-size calculation. The resulting oversized buffer operation can cause invalid or NULL pointers to be passed to the AP4_DataBuffer copy path, resulting in application termination and denial of service.
Published 2026-09-24
- HighCVSS 7.5 v3·EPSS 0.4%·No fix yet
Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC atom with a declared size smaller than the atom header size can cause the payload-size calculation to wrap to a large unsigned value. The resulting invalid buffer allocation and copy operations can cause application termination, leading to denial of service.
Published 2026-09-24
- MediumCVSS 5.1 v3·EPSS 0.1%·Fix available
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime. An attacker with root access to a partition can send a specially crafted request to the partition firmware runtime, causing it to crash with possible memory corruption.
Published 2026-09-24
- CVSS 3.3 v3·EPSS 0.1%·No fix yet
A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing a manipulation of the argument BlockSize results in integer underflow. The attack requires a local approach. The patch is named c372b6bbca9d8c63812be50596fefa4a79c65fd0. It is recommended to apply a patch to fix this issue.
Published 2026-09-23
- CVSS 3.3 v3·EPSS 0.1%·Fix available
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata section base, making subtraction produce a negative logical index. The vulnerability is triggered by parsing Swift type and class metadata from a crafted Mach-O file. The derived index was used to read four bytes immediately before the allocated field-metadata buffer. This can cause incorrect metadata processing or process termination; no attacker-observable memory disclosure has been demonstrated. This issue is fixed in version 6.2.0.
Published 2026-09-22
- HighCVSS 7.8 v3·EPSS 0.5%·Fix available
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Published 2026-09-21
- MediumCVSS 6.3 v3·EPSS 0.4%·No fix yet
A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the component PE Parser. The manipulation of the argument misc.Length results in integer underflow. The attack may be performed from remote. The patch is identified as 3e299685759f4f767088871de58c5d07f98ee382. A patch should be applied to remediate this issue.
Published 2026-09-20
- MediumCVSS 6.2 v3·EPSS 0.2%·Fix available
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one record. A crafted SF2 file containing a zero-sized DMOD chunk makes the unsigned subtraction wrap to UINT_MAX, and the parser then attempts billions of SFMod allocations. This exhausts process memory and causes denial of service. No workaround is available. This issue is fixed in version 2.5.6.
Published 2026-09-18
- MediumCVSS 5.3 v3·EPSS 0.4%·Fix available
A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but does not verify that the value is at least 5 (the minimum valid BSON document size) before using it in an array index calculation. When the length field is zero, the expression used to check the document's null terminator wraps to UINT32_MAX, causing a heap out-of-bounds read that crashes the process. An unauthorized party who can supply crafted BSON input to an application using this API can cause a denial of service.
Published 2026-09-17
- MediumCVSS 6.5 v3·EPSS 0.3%·Fix available
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabbitmq/amqp_connection.c. The parser subtracts HEADER_SIZE, fixed per-frame fields, and FOOTER_SIZE from state->target_size without first checking the minimum frame length. The wrapped encoded.len value is passed through amqp_decode_properties() to amqp_decode_table_internal(), where it defeats bounds checks and causes an out-of-bounds read and process crash. An on-path attacker can also trigger the issue when AMQP traffic is not protected by TLS with certificate validation. The demonstrated impact is denial of service, with no reliable memory disclosure or c
Published 2026-09-17
- CriticalCVSS 9.8 v3·EPSS 1.0%·Fix available
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
Published 2026-09-16
- HighCVSS 7.5 v3·EPSS 0.6%·No fix yet
MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that triggers an integer underflow, causing the resulting value to be used as the copy length in a memory copy operation into a smaller heap buffer, corrupting adjacent heap memory.
Published 2026-09-16
- HighCVSS 7.5 v3·EPSS 0.6%·No fix yet
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.
Published 2026-09-15
- MediumCVSS 4.0 v3·EPSS 0.1%·No fix yet
A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder.
Published 2026-09-14
- MediumCVSS 6.9 v4·EPSS 0.2%·No fix yet
An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.
Published 2026-09-11
- MediumCVSS 5.5 v3·EPSS 0.3%·Fix available
Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published 2026-09-08
- HighCVSS 5.5 v3·EPSS 0.4%·Fix available
Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
Published 2026-09-08
- HighCVSS 6.4 v3·EPSS 0.3%·Fix available
Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 8.8 v3·EPSS 0.9%·Fix available
Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.
Published 2026-09-08
- HighCVSS 7.0 v3·EPSS 0.2%·Fix available
Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 9.8 v3·EPSS 1.0%·Fix available
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
Published 2026-09-08
- HighCVSS 7.8 v3·EPSS 0.3%·Fix available
Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 7.8 v3·EPSS 0.3%·Fix available
Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 5.5 v3·EPSS 0.4%·Fix available
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
Published 2026-09-08
- HighCVSS 9.8 v3·EPSS 1.0%·Fix available
Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.
Published 2026-09-08
- HighCVSS 7.8 v3·EPSS 0.3%·Fix available
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighCVSS 8.0 v3·EPSS 0.8%·Fix available
Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.
Published 2026-09-08
Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.