CWE-681

CWE-681 · 5 records · 4 with a public proof-of-concept

Records the NVD classes under CWE-681, highest CVSS first.

  1. HIGH 7.5CVE-2026-88368public PoC

    NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() function. A specially crafted SVG document containing sufficiently large geometry coordinates can cause fixed-point-scaled edge coordinates to…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-88362

    MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted JavaScript input containing an excessively large numeric array index can cause an out-of-range floating-point value to be converted to an int…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.5CVE-2026-88367public PoC

    NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing an extremely large stroke-width can cause floating-point rounding to produce a zero subdi…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.5CVE-2026-88387public PoC

    LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, TIFF, or DNG file can supply an attacker-controlled NewSubfileType value outside the ran…

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-77412public PoC

    RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-array field with type tag x into a signed int32 and passes the value directly to make when allocating the field buffer. A malicious or comprom…

    AI risk analysis on Exploit-DB.ai →