CWE-680— Integer Overflow to Buffer Overflow
The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.— MITRE CWE catalog
113 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-680page 3 of 3
- CVE-2023-21648MEDIUMCVSS 6.7EG 6.72023-08-08
Memory corruption in RIL while trying to send apdu packet.
- CVE-2026-19588MEDIUMCVSS 6.5EG 6.52026-08-12
Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
- CVE-2023-22305MEDIUMCVSS 6.5EG 6.52023-11-14
Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-41175MEDIUMCVSS 6.5EG 6.52023-10-05
A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a…
- CVE-2025-54623MEDIUMCVSS 6.3EG 6.32025-08-06
Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2023-22443MEDIUMCVSS 6.0EG 6.02023-05-10
Integer overflow in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable denial of service via local access.
- CVE-2026-24928MEDIUMCVSS 5.5EG 5.82026-02-06
Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2022-29030MEDIUMCVSS 5.5EG 5.52022-05-20
A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The Mono_Loader.dll library is vulnerable to int…
- CVE-2026-81647MEDIUMCVSS 5.3EG 5.32026-09-09
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-6381MEDIUMCVSS 4.0EG 4.02024-07-02
The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson version…
- CVE-2020-15103LOWCVSS 3.5EG 3.52020-07-27
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates…
- CVE-2024-55626LOWCVSS 3.3EG 3.32025-01-06
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large BPF filter file provided to Suricata at startup can lead to a buffer overflow at Suricata startup…
- CVE-2024-57956LOWCVSS 2.8EG 2.82025-02-06
Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability may affect availability.
Map vulnerabilities like CWE-680 to your infrastructure
EchelonGraph correlates every CVE — across CWE-680 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →