CWE-680— Integer Overflow to Buffer Overflow
The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.— MITRE CWE catalog
113 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-680page 2 of 3
- CVE-2019-18568HIGHCVSS 8.8EG 8.82019-12-31
Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a restricted user.
- CVE-2019-5087HIGHCVSS 8.8EG 8.82019-11-21
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An integer overflow can occur while calculating the row's allocation size, that could be explo…
- CVE-2019-5086HIGHCVSS 8.8EG 8.82019-11-21
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to …
- CVE-2025-20263HIGHCVSS 8.6EG 8.62025-08-14
A vulnerability in the web services interface of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a buffer ove…
- CVE-2021-30354HIGHCVSS 8.6EG 8.62021-09-01
Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function CJBig2Image::expand() and results in a memory corruption that leads to code execution when par…
- CVE-2026-76825HIGHCVSS 8.4EG 8.42026-09-16
RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed t…
- CVE-2024-48877HIGHCVSS 8.4EG 8.42025-06-02
A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious fi…
- CVE-2024-21470HIGHCVSS 8.4EG 8.42024-04-01
Memory corruption while allocating memory for graphics.
- CVE-2024-2608HIGHCVSS 8.4EG 8.42024-03-19
`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability …
- CVE-2023-33022HIGHCVSS 8.4EG 8.42023-12-05
Memory corruption in HLOS while invoking IOCTL calls from user-space.
- CVE-2022-33282HIGHCVSS 8.4EG 8.42023-04-13
Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback.
- CVE-2022-40530HIGHCVSS 8.4EG 8.42023-03-10
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
- CVE-2026-55200HIGHCVSS 8.3EG 8.32026-06-17
libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessivel…
- CVE-2024-37305HIGHCVSS 8.2EG 8.22024-06-17
oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from liboqs. Flaws have been identified in the way oqs-provider handl…
- CVE-2023-28585HIGHCVSS 8.2EG 8.22023-12-05
Memory corruption while loading an ELF segment in TEE Kernel.
- CVE-2023-37536HIGHCVSS 8.2EG 8.22023-10-11
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
- CVE-2026-90783HIGHCVSS 7.8EG 7.82026-09-13
MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause…
- CVE-2026-43627HIGHCVSS 7.8EG 7.82026-08-06
llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass…
- CVE-2025-21442HIGHCVSS 7.8EG 7.82025-04-07
Memory corruption while transmitting packet mapping information with invalid header payload size.
- CVE-2024-38422HIGHCVSS 7.8EG 7.82024-11-04
Memory corruption while processing voice packet with arbitrary data received from ADSP.
- CVE-2023-33018HIGHCVSS 7.8EG 7.82023-12-05
Memory corruption while using the UIM diag command to get the operators name.
- CVE-2022-25705HIGHCVSS 7.8EG 7.82023-03-10
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
- CVE-2022-33248HIGHCVSS 7.8EG 7.82023-02-12
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.
- CVE-2022-32543HIGHCVSS 7.8EG 7.82022-08-05
An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in arbitrary code execution. An attacker can provide a malicious…
- CVE-2022-29886HIGHCVSS 7.8EG 7.82022-08-05
An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow, which can result in arbitrary code execution. An attacker can provide a maliciou…
- CVE-2020-6099HIGHCVSS 7.8EG 7.82022-04-18
An exploitable code execution vulnerability exists in the file format parsing functionality of Graphisoft BIMx Desktop Viewer 2019.2.2328. A specially crafted file can cause a heap buffer overflow resulting in a code execution. An attacker…
- CVE-2020-6116HIGHCVSS 7.8EG 7.82020-09-17
An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed colorspace, the application can miscalculat…
- CVE-2020-1895HIGHCVSS 7.8EG 7.82020-04-09
A large heap overflow could occur in Instagram for Android when attempting to upload an image with specially crafted dimensions. This affects versions prior to 128.0.0.26.128.
- CVE-2022-33296HIGHCVSS 5.9EG 7.82023-04-13
Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.
- CVE-2026-25541HIGHCVSS 7.5EG 7.52026-02-04
Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap …
- CVE-2025-23326HIGHCVSS 7.5EG 7.52025-08-06
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through a specially crafted input. A successful exploit of this vulnerability might lead to denial of service.
- CVE-2024-58107HIGHCVSS 7.5EG 7.52025-04-07
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-21454HIGHCVSS 7.5EG 7.52024-04-01
Transient DOS while decoding the ToBeSignedMessage in Automotive Telematics.
- CVE-2024-24478HIGHCVSS 7.5EG 7.52024-02-21
An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor beca…
- CVE-2021-3321HIGHCVSS 7.5EG 7.52021-10-12
Integer Underflow in Zephyr in IEEE 802154 Fragment Reassembly Header Removal. Zephyr versions >= >=2.4.0 contain Integer Overflow to Buffer Overflow (CWE-680). For more information, see https://github.com/zephyrproject-rtos/zephyr/securit…
- CVE-2021-41099HIGHCVSS 7.5EG 7.52021-10-04
Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the underlying string library can be used to corrupt the heap and potentially result with denial of service or remote code execution. The vulnera…
- CVE-2021-32762HIGHCVSS 7.5EG 7.52021-10-04
Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network replies. This is a …
- CVE-2021-32687HIGHCVSS 7.5EG 7.52021-10-04
Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the heap or trigger remot…
- CVE-2021-32628HIGHCVSS 7.5EG 7.52021-10-04
Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with remote code execution. …
- CVE-2021-32627HIGHCVSS 7.5EG 7.52021-10-04
Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnerability involves cha…
- CVE-2021-32761HIGHCVSS 7.5EG 7.52021-07-21
Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prior to versions 5.0.13, 6.0.15, and 6.2.5. On 32-bit systems,…
- CVE-2021-32625HIGHCVSS 7.5EG 7.52021-06-02
Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer, could be exploited using the STRALGO LCS command to corrupt the h…
- CVE-2022-24834HIGHCVSS 7.0EG 7.42023-07-13
Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The problem ex…
- CVE-2024-56451HIGHCVSS 7.3EG 7.32025-01-08
Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-32023HIGHCVSS 7.0EG 7.02025-07-07
Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap out of bounds write on hyperloglog ope…
- CVE-2022-36765HIGHCVSS 7.0EG 7.02024-01-09
EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confident…
- CVE-2026-70651MEDIUMCVSS 6.9EG 6.92026-08-20
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF th…
- CVE-2020-11038MEDIUMCVSS 6.9EG 6.92020-05-29
In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instruct the client to allocate a buffer with a smaller size than requested due to an integer ov…
- CVE-2024-28219MEDIUMCVSS 6.7EG 6.72024-04-03
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
- CVE-2023-21644MEDIUMCVSS 6.7EG 6.72023-09-05
Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.
Map vulnerabilities like CWE-680 to your infrastructure
EchelonGraph correlates every CVE — across CWE-680 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →