CWE-680
105 CVEs • Abstraction: Compound
Integer Overflow to Buffer Overflow
The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.
CVEs (105)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 114315 5g Iot Modem Firmware 8905 Firmware8909 Firmware+111 moreJun 17, 2026 Apr 13, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message. |
1Qualcomm 20Msm8996au Firmware Qam8295p FirmwareQca6574a Firmware+17 moreJun 17, 2026 Apr 13, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback. |
1Qualcomm 189Aqt1000 Firmware Ar8031 FirmwareAr8035 Firmware+186 moreJun 17, 2026 Mar 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase. |
1Qualcomm 201Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+198 moreJun 17, 2026 Mar 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response |
1Qualcomm 162Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+159 moreJun 17, 2026 Feb 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http. |
A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this...Show more |
An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in arbitrary code execution. An attacker can...Show more |
An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow, which can result in arbitrary code execution. An attacker can...Show more |
1Siemens 2Jt2go Teamcenter VisualizationJun 17, 2026 May 20, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The Mono_Loader.dll library i...Show more |
1Graphisoft 1Bimx Desktop Viewer Jun 17, 2026 Apr 18, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable code execution vulnerability exists in the file format parsing functionality of Graphisoft BIMx Desktop Viewer 2019.2.2328. A specially crafted file can cause a heap buffer overflow resulting in a code exe...Show more |
1Blackmagicdesign 1Davinci Resolve Jun 17, 2026 Dec 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitted with the job along with fields that were parsed for the submitted v...Show more |
Integer Underflow in Zephyr in IEEE 802154 Fragment Reassembly Header Removal. Zephyr versions >= >=2.4.0 contain Integer Overflow to Buffer Overflow (CWE-680). For more information, see https://github.com/zephyrproject-...Show more |
3Debian NetappRedis3Debian Linux HiredisManagement Services For Element Software And Netapp HciJun 17, 2026 Oct 4, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Hiredis is a minimalistic C client library for the Redis database. In affected versions Hiredis is vulnurable to integer overflow if provided maliciously crafted or corrupted `RESP` `mult-bulk` protocol data. When parsin...Show more |
5Debian FedoraprojectNetapp+2 more5Communications Operations Monitor Debian LinuxFedora+2 moreJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the underlying string library can be used to corrupt the heap and potentially result with denial of service or remote code exe...Show more |
5Debian FedoraprojectNetapp+2 more6Communications Operations Monitor Debian LinuxFedora+3 moreJun 17, 2026 Oct 4, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network...Show more |
5Debian FedoraprojectNetapp+2 more6Communications Operations Monitor Debian LinuxFedora+3 moreJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the he...Show more |
5Debian FedoraprojectNetapp+2 more6Communications Operations Monitor Debian LinuxFedora+3 moreJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with remo...Show more |
5Debian FedoraprojectNetapp+2 more6Communications Operations Monitor Debian LinuxFedora+3 moreJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnera...Show more |
Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function CJBig2Image::expand() and results in a memory corruption that leads to code...Show more |
An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow when th...Show more |