The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.
Volume of CVEs assigned to CWE-680 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
105 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24834HIGH Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corru | Jul 13, 2023 | 8.8 | 50 | NO | NO |
CVE-2026-55200HIGH libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Re | Jun 17, 2026 | 8.3 | 46 | NO | NO |
CVE-2021-32761HIGH Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prio | Jul 21, 2021 | 7.5 | 41 | NO | NO |
CVE-2026-8376CRITICAL Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.
Perl_study_chunk in regcomp_study.c che | May 25, 2026 | 9.8 | 40 | NO | NO |
CVE-2025-32023HIGH Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use a specially crafted string to | Jul 7, 2025 | 7.8 | 40 | NO | YES |
CVE-2018-8795CRITICAL rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_updates() and results in a memory cor | Feb 5, 2019 | 9.8 | 34 | NO | NO |
CVE-2018-8794CRITICAL rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results in a memory corruptio | Feb 5, 2019 | 9.8 | 34 | NO | NO |
CVE-2018-8787CRITICAL FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption an | Nov 29, 2018 | 9.8 | 34 | NO | NO |
CVE-2018-8786CRITICAL FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corrupt | Nov 29, 2018 | 9.8 | 34 | NO | NO |
CVE-2021-21783CRITICAL A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An att | Mar 25, 2021 | 9.8 | 33 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.