CWE-704— Incorrect Type Conversion or Cast
The product does not correctly convert an object, resource, or structure from one type to a different type.— MITRE CWE catalog
283 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-704page 5 of 6
- CVE-2021-38187CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the anymap crate through 0.12.1 for Rust. It violates soundness via conversion of a *u8 to a *u64.
- CVE-2021-39173HIGHCVSS 8.8EG 8.82021-08-27
Cachet is an open source status page system. Prior to version 2.5.1 authenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. Th…
- CVE-2021-39989HIGHCVSS 7.5EG 7.52022-01-03
The HwNearbyMain module has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability may cause a process to restart.
- CVE-2021-43537HIGHCVSS 8.8EG 8.82021-12-08
An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- CVE-2021-4456MEDIUMCVSS 6.5EG 6.52026-02-27
Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions `addr2cidr` and `cidrlookup` may return leading zeros in a CIDR string, which may in turn be parsed as …
- CVE-2022-0322MEDIUMCVSS 5.5EG 5.52022-03-25
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers…
- CVE-2022-1642HIGHCVSS 7.5EG 7.52022-06-16
A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a …
- CVE-2022-21786MEDIUMCVSS 6.7EG 6.72022-07-06
In audio DSP, there is a possible memory corruption due to improper casting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558822;…
- CVE-2022-22102HIGHCVSS 8.4EG 8.42022-09-02
Memory corruption in multimedia due to incorrect type conversion while adding data in Snapdragon Auto
- CVE-2022-25715HIGHCVSS 6.7EG 7.82023-01-09
Memory corruption in display driver due to incorrect type casting while accessing the fence structure fields
- CVE-2022-25852HIGHCVSS 7.5EG 7.52022-06-17
All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:*…
- CVE-2022-32547HIGHCVSS 7.8EG 7.82022-06-16
In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by Imag…
- CVE-2022-33240MEDIUMCVSS 6.7EG 6.72023-06-06
Memory corruption in Audio due to incorrect type cast during audio use-cases.
- CVE-2022-33301HIGHCVSS 6.7EG 7.82023-04-13
Memory corruption due to incorrect type conversion or cast in audio while using audio playback/capture when crafted address is sent from AGM IPC to AGM.
- CVE-2022-3979CRITICALCVSS 5.6EG 9.82022-11-13
A vulnerability was found in NagVis up to 1.9.33 and classified as problematic. This issue affects the function checkAuthCookie of the file share/server/core/classes/CoreLogonMultisite.php. The manipulation of the argument hash leads to in…
- CVE-2022-40531HIGHCVSS 8.4EG 8.42023-03-10
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
- CVE-2022-41668HIGHCVSS 7.0EG 7.82022-11-04
A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicious code. Affected P…
- CVE-2022-41828HIGHCVSS 8.1EG 8.12022-09-29
In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name.
- CVE-2022-41890MEDIUMCVSS 4.8EG 4.82022-11-18
TensorFlow is an open source platform for machine learning. If `BCast::ToShape` is given input larger than an `int32`, it will crash, despite being supposed to handle up to an `int64`. An example can be seen in `tf.experimental.numpy.outer…
- CVE-2022-41911MEDIUMCVSS 4.8EG 4.82022-11-18
TensorFlow is an open source platform for machine learning. When printing a tensor, we get it's data as a `const char*` array (since that's the underlying storage) and then we typecast it to the element type. However, conversions from `cha…
- CVE-2022-43663CRITICALCVSS 8.1EG 9.82023-03-20
An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a buffer overflow. An attacker can send a malicious packet to t…
- CVE-2022-49873MEDIUMCVSS 5.5EG 5.52025-05-01
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix wrong reg type conversion in release_reference() Some helper functions will allocate memory. To avoid memory leaks, the verifier requires the eBPF program to re…
- CVE-2023-21627MEDIUMCVSS 6.7EG 6.72023-08-08
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
- CVE-2023-21638MEDIUMCVSS 6.7EG 6.72023-07-04
Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.
- CVE-2023-21651CRITICALCVSS 9.3EG 9.32023-08-08
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
- CVE-2023-21665HIGHCVSS 8.4EG 8.42023-05-02
Memory corruption in Graphics while importing a file.
- CVE-2023-25737HIGHCVSS 8.8EG 8.82023-06-02
An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
- CVE-2023-28162HIGHCVSS 8.8EG 8.82023-06-02
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird …
- CVE-2023-33101HIGHCVSS 7.5EG 7.52024-04-01
Transient DOS while processing DL NAS TRANSPORT message with payload length 0.
- CVE-2023-35816LOWCVSS 3.5EG 3.52025-04-28
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
- CVE-2023-45204HIGHCVSS 7.8EG 7.82023-10-10
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain a type confusion vulnerability while par…
- CVE-2023-6249HIGHCVSS 8.0EG 8.02024-02-18
Signed to unsigned conversion esp32_ipm_send
- CVE-2023-7345MEDIUMCVSS 6.5EG 6.52026-05-19
Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting incorrect hexadecimal field parsing when va…
- CVE-2024-21478MEDIUMCVSS 6.2EG 6.22024-06-03
transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.
- CVE-2024-26015LOWCVSS 3.4EG 3.42024-07-09
An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and FortiOS version 7.4.3 and below, version 7.2.8 and below, version…
- CVE-2024-2606LOWCVSS 3.7EG 3.72024-03-19
Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Firefox < 124.
- CVE-2024-28130HIGHCVSS 7.5EG 7.52024-04-23
An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a maliciou…
- CVE-2024-32893HIGHCVSS 5.5EG 8.12024-06-13
In _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper casting. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2024-35303HIGHCVSS 7.8EG 7.82024-06-11
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0012), Tecnomatix Plant Simulation V2404 (All versions < V2404.0001). The affected applications contain a type confusion vulnerability while par…
- CVE-2024-36735MEDIUMCVSS 5.3EG 5.32024-06-06
OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter is floating.
- CVE-2024-39589HIGHCVSS 7.5EG 7.52024-09-18
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of servic…
- CVE-2024-39590HIGHCVSS 7.5EG 7.52024-09-18
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of servic…
- CVE-2024-43058HIGHCVSS 7.8EG 7.82025-04-07
Memory corruption while processing IOCTL calls.
- CVE-2024-47181HIGHCVSS 7.5EG 7.52024-11-27
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An unaligned memory access can be triggered in the two RPL implementations of the Contiki-NG operating system. The problem can occur when either one of these RP…
- CVE-2024-5436CRITICALCVSS 9.8EG 9.82024-05-31
Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.
- CVE-2024-57839MEDIUMCVSS 5.5EG 5.52025-01-11
In the Linux kernel, the following vulnerability has been resolved: Revert "readahead: properly shorten readahead when falling back to do_page_cache_ra()" This reverts commit 7c877586da3178974a8a94577b6045a48377ff25. Anders and Philippe…
- CVE-2025-1057MEDIUMCVSS 4.3EG 4.32025-03-15
A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prevents the registrar from reading database entries created by previous versions, for example, 7.11.0. Specifically, older…
- CVE-2025-12781MEDIUMCVSS 5.3EG 5.32026-01-21
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish …
- CVE-2025-13720HIGHCVSS 8.8EG 8.82025-12-02
Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-20072MEDIUMCVSS 6.5EG 6.52025-01-16
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.
Map vulnerabilities like CWE-704 to your infrastructure
EchelonGraph correlates every CVE — across CWE-704 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →