CWE-680

Integer Overflow to Buffer Overflow

Parent: CWE-190 - Integer Overflow or Wraparound

The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.

104 vulnerabilities with CWE-680
CVE-2026-8376 CRITICAL
Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
CVSS 9.8
CVE-2026-24928 MEDIUM
Huawei EMUI - Out-of-bounds Write in File System Module
CVSS 5.8
CVE-2026-25541 HIGH
Bytes 1.2.1-1.11.0 - Integer Overflow to Buffer Overflow in BytesMut::reserve
CVSS 7.5
CVE-2025-53510 HIGH
SAIL Image Decoding Library v0.9.8 - Memory Corruption
CVSS 8.8
CVE-2025-52930 HIGH
SAIL Image Decoding Library 0.9.8 - Remote Code Execution via BMPv3 RLE Decoding
CVSS 8.8
CVE-2025-52456 HIGH
SAIL Image Decoding Library 0.9.8 - Remote Code Execution via WebP Animation Stride Calculation Overflow
CVSS 8.8
CVE-2025-46407 HIGH
SAIL Image Decoding Library v0.9.8 - Memory Corruption
CVSS 8.8
CVE-2025-32468 HIGH
SAIL Image Decoding Library 0.9.8 - Remote Code Execution via BMPv3 Image Decoding
CVSS 8.8
CVE-2025-20263 HIGH
Cisco Secure Firewall - Buffer Overflow
CVSS 8.6
CVE-2025-54952 CRITICAL
ExecuTorch <8f062d3f661e20bb19b24b767b9a9a46e8359f2b - Code Injection
CVSS 9.8
CVE-2025-23326 HIGH
NVIDIA Triton Inference Server < 25.05 - Denial of Service via Integer Overflow
CVSS 7.5
CVE-2025-54623 MEDIUM
HarmonyOS - Out-of-bounds Read in DeviceManager Module
CVSS 6.3
CVE-2025-53630 HIGH
llama.cpp - Heap-based Buffer Overflow in gguf_init_from_file_impl
CVE-2025-32023 HIGH
Redis 2.8.0-6.2.18 - Authenticated Remote Code Execution via HyperLogLog String Parsing
CVSS 7.0
CVE-2025-21442 HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2024-48877 HIGH
xls2csv 0.95 - Heap Buffer Overflow in Shared String Table Record Parser
CVSS 8.4
CVE-2024-58107 HIGH
HarmonyOS - Buffer Overflow in Codec Module
CVSS 7.5
CVE-2024-57956 LOW
HarmonyOS - Out-of-bounds Read in Interpreter String Module
CVSS 2.8
CVE-2024-56451 HIGH
HarmonyOS - Integer Overflow in 3D Engine glTF Model Loading
CVSS 7.3
CVE-2024-55626 LOW
Suricata < 7.0.8 - Buffer Overflow via Large BPF Filter File
CVSS 3.3
CVE-2024-38422 HIGH
Qualcomm Mobile Platform and Modem Firmware - Memory Corruption
CVSS 7.8
CVE-2024-6381 MEDIUM
MongoDB <1.26.2 - Memory Corruption
CVSS 4.0
CVE-2024-37305 HIGH
oqs-provider < 0.6.1 - Buffer Overflow via DECODE_UINT32 Length Handling
CVSS 8.2
CVE-2024-33078 CRITICAL
Tencent Libpag v4.3 - Buffer Overflow via Crafted Image
CVSS 9.8
CVE-2024-28219 MEDIUM
Pillow < 10.3.0 - Buffer Overflow via Unsafe strcpy in _imagingcms.c
CVSS 6.7
Details
Vulnerabilities 104