The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.
104 vulnerabilities with CWE-680
CVE-2026-8376
CRITICAL
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
CVSS 9.8
CVE-2026-24928
MEDIUM
Huawei EMUI - Out-of-bounds Write in File System Module
CVSS 5.8
CVE-2026-25541
HIGH
Bytes 1.2.1-1.11.0 - Integer Overflow to Buffer Overflow in BytesMut::reserve
CVSS 7.5
CVE-2025-53510
HIGH
SAIL Image Decoding Library v0.9.8 - Memory Corruption
CVSS 8.8
CVE-2025-52930
HIGH
SAIL Image Decoding Library 0.9.8 - Remote Code Execution via BMPv3 RLE Decoding
CVSS 8.8
CVE-2025-52456
HIGH
SAIL Image Decoding Library 0.9.8 - Remote Code Execution via WebP Animation Stride Calculation Overflow
CVSS 8.8
CVE-2025-46407
HIGH
SAIL Image Decoding Library v0.9.8 - Memory Corruption
CVSS 8.8
CVE-2025-32468
HIGH
SAIL Image Decoding Library 0.9.8 - Remote Code Execution via BMPv3 Image Decoding
CVSS 8.8
CVE-2025-20263
HIGH
Cisco Secure Firewall - Buffer Overflow
CVSS 8.6
CVE-2025-54952
CRITICAL
ExecuTorch <8f062d3f661e20bb19b24b767b9a9a46e8359f2b - Code Injection
CVSS 9.8
CVE-2025-23326
HIGH
NVIDIA Triton Inference Server < 25.05 - Denial of Service via Integer Overflow
CVSS 7.5
CVE-2025-54623
MEDIUM
HarmonyOS - Out-of-bounds Read in DeviceManager Module
CVSS 6.3
CVE-2025-53630
HIGH
llama.cpp - Heap-based Buffer Overflow in gguf_init_from_file_impl
CVE-2025-32023
HIGH
Redis 2.8.0-6.2.18 - Authenticated Remote Code Execution via HyperLogLog String Parsing
CVSS 7.0
CVE-2025-21442
HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2024-48877
HIGH
xls2csv 0.95 - Heap Buffer Overflow in Shared String Table Record Parser
CVSS 8.4
CVE-2024-58107
HIGH
HarmonyOS - Buffer Overflow in Codec Module
CVSS 7.5
CVE-2024-57956
LOW
HarmonyOS - Out-of-bounds Read in Interpreter String Module
CVSS 2.8
CVE-2024-56451
HIGH
HarmonyOS - Integer Overflow in 3D Engine glTF Model Loading
CVSS 7.3
CVE-2024-55626
LOW
Suricata < 7.0.8 - Buffer Overflow via Large BPF Filter File
CVSS 3.3
CVE-2024-38422
HIGH
Qualcomm Mobile Platform and Modem Firmware - Memory Corruption
CVSS 7.8
CVE-2024-6381
MEDIUM
MongoDB <1.26.2 - Memory Corruption
CVSS 4.0
CVE-2024-37305
HIGH
oqs-provider < 0.6.1 - Buffer Overflow via DECODE_UINT32 Length Handling
CVSS 8.2
CVE-2024-33078
CRITICAL
Tencent Libpag v4.3 - Buffer Overflow via Crafted Image
CVSS 9.8
CVE-2024-28219
MEDIUM
Pillow < 10.3.0 - Buffer Overflow via Unsafe strcpy in _imagingcms.c
CVSS 6.7
Details
Vulnerabilities
104