CWE-681
108 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-681page 2 of 3
- CVE-2021-32629HIGHCVSS 7.2EG 7.22021-05-24
Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermediate representation into executable machine code. There is a bug in 0.73 of the Cranelift x64 backend that can create a …
- CVE-2021-32996HIGHCVSS 7.5EG 7.52022-01-10
The FANUC R-30iA and R-30iB series controllers are vulnerable to integer coercion errors, which cause the device to crash. A restart is required.
- CVE-2021-33742HIGHCVSS 7.5EG 9.0⚠ KEV2021-06-08
Windows MSHTML Platform Remote Code Execution Vulnerability
- CVE-2021-3444HIGHCVSS 7.8EG 7.82021-03-23
The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads i…
- CVE-2021-36357CRITICALCVSS 9.8EG 9.82021-10-22
An issue was discovered in OpenPOWER 2.6 firmware. unpack_timestamp() calls le32_to_cpu() for endian conversion of a uint16_t "year" value, resulting in a type mismatch that can truncate a higher integer value to a smaller one, and bypass …
- CVE-2021-37645MEDIUMCVSS 5.5EG 5.52021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.QuantizeAndDequantizeV4Grad` is vulnerable to an integer overflow issue caused by converting a signed integer val…
- CVE-2021-37646MEDIUMCVSS 5.5EG 5.52021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of `tf.raw_ops.StringNGrams` is vulnerable to an integer overflow issue caused by converting a signed integer value to an unsign…
- CVE-2021-37661MEDIUMCVSS 5.5EG 5.52021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause a denial of service in `boosted_trees_create_quantile_stream_resource` by using negative arguments. The [implementation](http…
- CVE-2021-37669MEDIUMCVSS 5.5EG 5.52021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause denial of service in applications serving models using `tf.raw_ops.NonMaxSuppressionV5` by triggering a division by 0. The [i…
- CVE-2021-37679HIGHCVSS 7.1EG 7.12021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions it is possible to nest a `tf.map_fn` within another `tf.map_fn` call. However, if the input tensor is a `RaggedTensor` and there is no function sig…
- CVE-2021-38187CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the anymap crate through 0.12.1 for Rust. It violates soundness via conversion of a *u8 to a *u64.
- CVE-2021-41202MEDIUMCVSS 5.5EG 5.52021-11-05
TensorFlow is an open source platform for machine learning. In affected versions while calculating the size of the output within the `tf.range` kernel, there is a conditional statement of type `int64 = condition ? int64 : double`. Due to C…
- CVE-2021-41272HIGHCVSS 7.5EG 7.52021-12-13
Besu is an Ethereum client written in Java. Starting in version 21.10.0, changes in the implementation of the SHL, SHR, and SAR operations resulted in the introduction of a signed type coercion error in values that represent negative value…
- CVE-2022-0322MEDIUMCVSS 5.5EG 5.52022-03-25
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers…
- CVE-2022-2639HIGHCVSS 7.8EG 7.82022-09-01
An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZ…
- CVE-2022-27189HIGHCVSS 7.5EG 7.52022-05-05
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when an Internet Content Adaptation Protocol (ICA…
- CVE-2022-27882HIGHCVSS 7.5EG 7.52022-03-25
slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can prevent exploitation.
- CVE-2022-34169HIGHCVSS 7.5EG 7.52022-07-19
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java by…
- CVE-2022-34670HIGHCVSS 7.8EG 7.82022-12-30
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause truncation errors when casting a primitive to a primitive of smaller size causes data to be lost in…
- CVE-2022-34677MEDIUMCVSS 5.5EG 5.52022-12-30
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tampering.
- CVE-2022-34680MEDIUMCVSS 5.5EG 5.52022-12-30
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of service.
- CVE-2022-36025CRITICALCVSS 9.1EG 9.12022-09-24
Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect Conversion between Numeric Types. An error in 32 bit signed and unsigned types in the calculation of available gas in …
- CVE-2022-40138CRITICALCVSS 9.8EG 9.82022-10-11
An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and subsequently execute arbitrary code. Note that this is only e…
- CVE-2022-40225MEDIUMCVSS 6.5EG 6.52022-11-10
A vulnerability has been identified in SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6GK7543-1MX00-0XE0) (All versions < V2.4.8). Casting an internal value could lead to floating point exception under cert…
- CVE-2022-42324MEDIUMCVSS 5.5EG 5.52022-11-01
Oxenstored 32->31 bit integer truncation issues Integers in Ocaml are 63 or 31 bits of signed precision. The Ocaml Xenbus library takes a C uint32_t out of the ring and casts it directly to an Ocaml integer. In 64-bit Ocaml builds this is …
- CVE-2022-43663HIGHCVSS 8.1EG 9.82023-03-20
An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a buffer overflow. An attacker can send a malicious packet to t…
- CVE-2023-0185MEDIUMCVSS 6.7EG 7.12023-04-01
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where sign conversion issuescasting an unsigned primitive to signed may lead to denial of service or information disclosure.
- CVE-2023-20006HIGHCVSS 8.6EG 8.62023-06-28
A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauth…
- CVE-2023-21736HIGHCVSS 7.8EG 7.82023-01-10
Microsoft Office Visio Remote Code Execution Vulnerability
- CVE-2023-23388HIGHCVSS 8.8EG 8.82023-03-14
Windows Bluetooth Driver Elevation of Privilege Vulnerability
- CVE-2023-23401HIGHCVSS 7.8EG 7.82023-03-14
Windows Media Remote Code Execution Vulnerability
- CVE-2023-24884HIGHCVSS 8.8EG 8.82023-04-11
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-28063MEDIUMCVSS 6.7EG 6.72024-02-06
Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.
- CVE-2023-29346HIGHCVSS 7.8EG 7.82023-06-14
NTFS Elevation of Privilege Vulnerability
- CVE-2023-3635MEDIUMCVSS 5.9EG 5.92023-07-12
GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
- CVE-2023-46848HIGHCVSS 8.6EG 8.62023-11-03
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
- CVE-2023-5184HIGHCVSS 7.0EG 7.02023-09-27
Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the Zephyr IPM drivers.
- CVE-2024-1552HIGHCVSS 7.5EG 7.52024-02-20
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird …
- CVE-2024-26162HIGHCVSS 8.8EG 8.82024-03-12
Microsoft ODBC Driver Remote Code Execution Vulnerability
- CVE-2024-32481MEDIUMCVSS 5.3EG 5.32024-04-25
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to version 0.4.0b1, when looping over a `range` of the form `range(start, start + N)`, if `start` is negative, the execution …
- CVE-2024-38044HIGHCVSS 7.2EG 7.22024-07-09
DHCP Server Service Remote Code Execution Vulnerability
- CVE-2024-49093HIGHCVSS 8.8EG 8.82024-12-12
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
- CVE-2024-7747MEDIUMCVSS 6.5EG 6.52024-11-28
The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versions up to, and including, 1.5.6. This is due to a numerical logic flaw when transferring funds to another user. This ma…
- CVE-2025-10543MEDIUMCVSS 5.3EG 5.32025-12-02
In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds 65535 bytes. This may lead to unexpected content in packets sent to…
- CVE-2025-24059HIGHCVSS 7.8EG 7.82025-03-11
Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-53733HIGHCVSS 8.4EG 8.42025-08-12
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-58063HIGHCVSS 7.1EG 7.12025-09-09
CoreDNS is a DNS server that chains plugins. Starting in version 1.2.0 and prior to version 1.12.4, the CoreDNS etcd plugin contains a TTL confusion vulnerability where lease IDs are incorrectly used as TTL values, enabling DNS cache pinni…
- CVE-2025-71002MEDIUMCVSS 6.5EG 6.52026-01-28
A floating-point exception (FPE) in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2026-21673HIGHCVSS 7.8EG 7.82026-01-06
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have overflows and underflows in CIccXmlArrayType::ParseTextCountNum(). This vulnerability affects users of the iccDEV l…
- CVE-2026-21688HIGHCVSS 8.8EG 8.82026-01-07
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in …
Map vulnerabilities like CWE-681 to your infrastructure
EchelonGraph correlates every CVE — across CWE-681 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →