CWE-680

Integer Overflow to Buffer Overflow

Parent: CWE-190 - Integer Overflow or Wraparound

The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.

104 vulnerabilities with CWE-680
CVE-2021-21847 HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow in MPEG-4 stts Decoder
CVSS 8.8
CVE-2021-21846 HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow via MPEG-4 stsz Decoder
CVSS 8.8
CVE-2021-21845 HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow via MPEG-4 stsc Decoder
CVSS 8.8
CVE-2021-21844 HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow via MPEG-4 stco Atom
CVSS 8.8
CVE-2021-21843 HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow via MPEG-4 Decoding
CVSS 8.8
CVE-2021-21839 HIGH
GPAC Project on Advanced Content 1.0.1 - Heap-Based Buffer Overflow via MPEG-4 Decoding
CVSS 8.8
CVE-2021-21838 HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow via MPEG-4 Decoding
CVSS 8.8
CVE-2021-21837 HIGH
GPAC 1.0.1 - Integer Overflow to Heap-Based Buffer Overflow in MPEG-4 Decoder
CVSS 8.8
CVE-2021-21832 CRITICAL
Disc Soft Daemon Tools Pro 8.3.0.0767 - Memory Corruption via ISO Parsing
CVSS 9.8
CVE-2021-21861 HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow via MPEG-4 hdlr FOURCC Handling
CVSS 8.8
CVE-2021-21860 HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow via MPEG-4 'trik' FOURCC Parsing
CVSS 8.8
CVE-2021-21859 HIGH
GPAC 1.0.1 - Integer Truncation in MPEG-4 Atom Processing
CVSS 8.8
CVE-2021-32761 HIGH
Redis <5.0.13,6.0.15,6.2.5 - Buffer Overflow
CVSS 7.5
CVE-2021-32625 HIGH
Redis 6.0.0-6.0.13 - Remote Code Execution via STRALGO LCS Command Integer Overflow
CVSS 7.5
CVE-2021-21783 CRITICAL
Genivia gSOAP 2.8.107 - Remote Code Execution via WS-Addressing Plugin
CVSS 9.8
CVE-2020-6099 HIGH
Graphisoft BIMx Desktop Viewer <2019.2.2328 - RCE
CVSS 7.8
CVE-2020-13576 CRITICAL
gSOAP 2.8.107 - Remote Code Execution via WS-Addressing Plugin
CVSS 9.8
CVE-2020-6116 HIGH
Nitro Pro 13.13.2.242 - Code Injection
CVSS 7.8
CVE-2020-10929 HIGH
NETGEAR R6700 V1.0.4.84_10.0.58 - Code Injection
CVSS 8.8
CVE-2020-15103 LOW
FreeRDP <= 2.1.2 - Integer Overflow in rdpegfx Channel
CVSS 3.5
CVE-2020-11038 MEDIUM
FreeRDP <= 2.0.0 - Integer Overflow to Buffer Overflow via Video Redirection
CVSS 6.9
CVE-2020-1895 HIGH
Instagram for Android <128.0.0.26.128 - Buffer Overflow
CVSS 7.8
CVE-2019-18568 HIGH
Avira Free Antivirus <15.0.1907.1514 - Privilege Escalation
CVSS 8.8
CVE-2019-5087 HIGH
xcftools 1.0.7 - Integer Overflow in flattenIncrementally Function
CVSS 8.8
CVE-2019-5086 HIGH
xcftools 1.0.7 - Integer Overflow in flattenIncrementally Function
CVSS 8.8
Details
Vulnerabilities 104