Vulnerabilities > Integer Underflow (Wrap or Wraparound)

DATE CVE VULNERABILITY TITLE RISK
2018-02-28 CVE-2018-7569 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (integer underflow or overflow, and application crash) via an ELF file with a corrupt DWARF FORM block, as demonstrated by nm.
network
gnu redhat CWE-191
4.3
2018-02-04 CVE-2018-6612 Integer Underflow (Wrap or Wraparound) vulnerability in Jhead Project Jhead 3.0
An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-service attack or unspecified other impact.
4.3
2018-01-09 CVE-2015-1208 Integer Underflow (Wrap or Wraparound) vulnerability in Ffmpeg
Integer underflow in the mov_read_default function in libavformat/mov.c in FFmpeg before 2.4.6 allows remote attackers to obtain sensitive information from heap and/or stack memory via a crafted MP4 file.
local
low complexity
ffmpeg CWE-191
5.5
2017-10-24 CVE-2017-15874 Integer Underflow (Wrap or Wraparound) vulnerability in Busybox 1.27.2
archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.
network
busybox CWE-191
4.3
2017-10-04 CVE-2017-14997 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c.
network
low complexity
graphicsmagick debian CWE-191
6.5
2017-10-03 CVE-2017-14496 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
7.5
2017-09-28 CVE-2017-14796 Integer Underflow (Wrap or Wraparound) vulnerability in Libbpg Project Libbpg 0.9.7
The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (integer underflow and application crash) or possibly have unspecified other impact via a crafted BPG file, related to improper interaction with copy_CTB_to_hv in hevc_filter.c in libavcodec in FFmpeg and sao_filter_CTB in hevc_filter.c in libavcodec in FFmpeg.
6.8
2017-08-24 CVE-2017-13666 Integer Underflow (Wrap or Wraparound) vulnerability in Multicorewareinc X265
An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x265 through 2.5, as used in libbpg and other products.
local
low complexity
multicorewareinc CWE-191
2.1
2017-08-09 CVE-2015-2311 Integer Underflow (Wrap or Wraparound) vulnerability in Capnproto
Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or possibly obtain sensitive information from memory or execute arbitrary code via a crafted message.
network
low complexity
capnproto CWE-191
7.5
2017-07-31 CVE-2017-11757 Integer Underflow (Wrap or Wraparound) vulnerability in Actian Pervasive Psql and ZEN
Heap-based buffer overflow in Actian Pervasive PSQL v12.10 and Zen v13 allows remote attackers to execute arbitrary code via crafted traffic to TCP port 1583.
network
low complexity
actian CWE-191
7.5