GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to deni
An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, cou
Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb
An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, whil
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged reg
The FANUC R-30iA and R-30iB series controllers are vulnerable to integer coercion errors, which cause the device to cras
slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT styleshee
A vulnerability has been identified in SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the
Oxenstored 32->31 bit integer truncation issues Integers in Ocaml are 63 or 31 bits of signed precision. The Ocaml Xenbu
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged reg
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncati
A vulnerability was found in FFmpeg 2.0. It has been declared as problematic. Affected by this vulnerability is the func
A vulnerability was found in FFmpeg 2.0. It has been classified as problematic. Affected is an unknown function of the f
An issue was discovered in the anymap crate through 0.12.1 for Rust. It violates soundness via conversion of a *u8 to a
An issue was discovered in OpenPOWER 2.6 firmware. unpack_timestamp() calls le32_to_cpu() for endian conversion of a uin
Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We p
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on A
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on A
An exploitable sign extension vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2
An exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Offic
The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source regis
Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Integer Truncation Privilege Es
An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with
An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer ov
django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before versi
Besu is an Ethereum client written in Java. Starting in version 21.10.0, changes in the implementation of the SHL, SHR,
Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermedi
TensorFlow is an end-to-end open source platform for machine learning. In affected versions it is possible to nest a `tf
In C2SoftMP3::process() of C2SoftMp3Dec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This
An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.ra
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.ra
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause a deni
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause denial
TensorFlow is an open source platform for machine learning. In affected versions while calculating the size of the outpu
TensorFlow is an end-to-end open source platform for machine learning. Calling `tf.raw_ops.ImmutableConst`(https://www.t
An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha)
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calli
An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c0
While handling the vendor command there is an integer truncation issue that could yield a buffer overflow due to int dat
Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local acc
uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bou
Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a la
An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack compone
Frequently Asked Questions
What is CWE-681?
CWE-681 (CWE-681) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-681?
There are 147 CVE records associated with CWE-681 in our database. Of these, 8 are critical severity, 71 are high severity, and 38 are medium severity.
How can I protect against CWE-681 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-681 using AI-powered security agents.
Detect CWE-681 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-681 vulnerabilities across your infrastructure.
Get Started