CWE-680Compound

Integer Overflow to Buffer Overflow

Draft in the CWE catalog · 103 CVEs mapped

103
CVEs mapped
8.4
Median CVSS
What it is

The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.

Recent examples
none
CVE-2026-19313

CVE-2026-19313 - UNKNOWN Severity Vulnerability

An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

no explanation yet
0%
epss
none
CVE-2026-70651

CVE-2026-70651 - UNKNOWN Severity Vulnerability

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The vulnerable calculations in libvips/foreign/magick6load.c and libvips/foreign/magick7load.c multiply the per-page Ysize by n_frames without a checked bound, which can cause a heap buffer over-read and process crash. Most package-manager builds include libtiff and do not use this affected fallback path. This issue is fixed in version 8.18.3.

no explanation yet
0%
epss
6.5cvss
CVE-2026-19588

CVE-2026-19588 - MEDIUM Severity Vulnerability

Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-680
Abstraction
Compound
Structure
Chain
Status
Draft
References (1)