Cyber Resilience

CWE · MITRE source

CWE-191Integer Underflow (Wrap or Wraparound)

Abstraction: Base · CVEs in our corpus: 523

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

This can happen in signed and unsigned cases.

Last updated: 11 August 2026 21:18 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SA-11 Developer Testing and Evaluation
  • ID.RA-01
  • PR.PS-02
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2014-0497 KEV 9.99.80.99882014-02-05
CVE-2024-380639.89.80.70562024-08-13
CVE-2022-0185 KEV 8.98.40.25152022-02-11
CVE-2023-42118 8.68.80.51752024-05-03
CVE-2005-0199 8.59.80.18772005-05-02
CVE-2021-31956 KEV 8.57.80.20272021-06-08
CVE-2020-36221 8.47.50.84222021-01-26
CVE-2020-36228 8.47.50.83382021-01-26
CVE-2023-31102 8.47.80.71042023-11-03
CVE-2017-14496 8.37.50.66352017-10-03
CVE-2016-10166 8.29.80.10692017-03-15
CVE-2018-20180 8.19.80.08212019-03-15
CVE-2018-20181 8.19.80.08212019-03-15
CVE-2018-20179 8.09.80.06792019-03-15
CVE-2020-15900 7.99.80.05192020-07-28
CVE-2016-1925 7.89.80.02992017-01-23
CVE-2017-9214 7.89.80.02892017-05-23
CVE-2018-14353 7.89.80.03702018-07-17
CVE-2018-14817 7.89.80.03582018-09-26
CVE-2020-28194 7.89.80.03002021-02-01
CVE-2015-0537 7.79.80.02642015-08-20
CVE-2017-8911 7.79.80.01932017-05-12
CVE-2017-11757 7.79.80.02492017-07-31
CVE-2015-2311 7.79.80.02542017-08-09
CVE-2019-14192 7.79.80.02702019-07-31