VYPR

CWE-680

Integer Overflow to Buffer Overflow

CompoundDraft

Description

The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-100 · CAPEC-14 · CAPEC-24 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-67 · CAPEC-8 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (112)

page 5 of 6
  • CVE-2020-11038MedMay 29, 2020
    risk 0.45cvss 6.9epss 0.01

    In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instruct the client to allocate a buffer with a smaller size than requested due to an integer overflow in size calculation. With later…

  • CVE-2026-90783HigSep 13, 2026
    risk 0.44cvss 7.8epss 0.00

    MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing…

  • CVE-2023-21644MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.

  • CVE-2023-21648MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in RIL while trying to send apdu packet.

  • CVE-2026-25541HigFeb 4, 2026
    risk 0.42cvss 7.5epss 0.01

    Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap + offset" uses an unchecked addition.…

  • CVE-2023-22305MedNov 14, 2023
    risk 0.42cvss 6.5epss 0.00

    Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2025-54623MedAug 6, 2025
    risk 0.41cvss 6.3epss 0.00

    Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-22443MedMay 10, 2023
    risk 0.39cvss 6.0epss 0.00

    Integer overflow in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable denial of service via local access.

  • CVE-2026-70651MedAug 20, 2026
    risk 0.38cvss —epss 0.00

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The…

  • CVE-2026-24928MedFeb 6, 2026
    risk 0.38cvss 5.8epss 0.00

    Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2022-33296MedApr 13, 2023
    risk 0.38cvss 5.9epss 0.00

    Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.

  • CVE-2024-28219MedApr 3, 2024
    risk 0.37cvss 6.7epss 0.01

    In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

  • CVE-2022-29030MedMay 20, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The Mono_Loader.dll library is vulnerable to integer overflow condition while parsing…

  • CVE-2026-19588MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.

  • CVE-2026-81647MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-6381MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2

  • CVE-2024-57956LowFeb 6, 2025
    risk 0.18cvss 2.8epss 0.00

    Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-32023HigJul 7, 2025
    risk 0.03cvss 7.0epss 0.04

    Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to trigger a stack/heap out of bounds write on hyperloglog operations, potentially leading to remote…

  • CVE-2018-8795CriFeb 5, 2019
    risk 0.01cvss 9.8epss 0.07

    rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_updates() and results in a memory corruption and probably even a remote code execution.

  • CVE-2018-8794CriFeb 5, 2019
    risk 0.01cvss 9.8epss 0.07

    rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results in a memory corruption and possibly even a remote code execution.