CWE-191

CWE-191 · 10 records · 7 with a public proof-of-concept

Records the NVD classes under CWE-191, highest CVSS first.

  1. HIGH 7.5CVE-2026-88376public PoC

    Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC atom with a declared size smaller than the atom header size can cause the payload-size calc…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-89028

    MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can …

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-71202public PoC

    The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only clamps the offset_x/offset_y parameters against 0, never against the source width/height.

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.8CVE-2026-18747public PoC

    The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len -= 2U; in mcumgr_serial_process_frag() (subsys/mgmt/mcumgr/transport/src/s…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 6.5CVE-2026-24077

    Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.

    aqt1000 firmware · aqt1000 · ar8035 firmware · ar8035 · csra6620 firmware · csra6620

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 6.3CVE-2026-94090public PoC

    A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the component PE Parser. The manipulation of the argument misc.Length results in integer underflow. The attack…

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 6.2CVE-2026-88377public PoC

    Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE can cause AP4_AvccAtom::Create() or AP4_HvccAtom:…

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 5.1CVE-2026-17504

    IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime. An attacker with root access to a partition can send a…

    AI risk analysis on Exploit-DB.ai →

  9. LOW 3.3CVE-2026-95958public PoC

    A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing a manipulation of the argument BlockSize results in integer underflow. The attac…

    AI risk analysis on Exploit-DB.ai →

  10. LOW 3.3CVE-2026-81881public PoC

    radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata section base, making subtra…

    radare2

    AI risk analysis on Exploit-DB.ai →