CWE-681— Incorrect Conversion between Numeric Types
When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.— MITRE CWE catalog
147 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-681page 1 of 3
- CVE-2020-17087CRITICALCVSS 7.8EG 9.0⚠ KEV2020-11-11
Windows Kernel Local Elevation of Privilege Vulnerability
- CVE-2021-33742CRITICALCVSS 7.5EG 9.0⚠ KEV2021-06-08
Windows MSHTML Platform Remote Code Execution Vulnerability
- CVE-2022-40138CRITICALCVSS 9.8EG 9.82022-10-11
An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and subsequently execute arbitrary code. Note that this is only e…
- CVE-2021-36357CRITICALCVSS 9.8EG 9.82021-10-22
An issue was discovered in OpenPOWER 2.6 firmware. unpack_timestamp() calls le32_to_cpu() for endian conversion of a uint16_t "year" value, resulting in a type mismatch that can truncate a higher integer value to a smaller one, and bypass …
- CVE-2021-38187CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the anymap crate through 0.12.1 for Rust. It violates soundness via conversion of a *u8 to a *u64.
- CVE-2020-35926CRITICALCVSS 9.8EG 9.82020-12-31
An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha) to return all zeroes because integer truncation was mishandled.
- CVE-2019-19317CRITICALCVSS 9.8EG 9.82019-12-05
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact.
- CVE-2019-14842CRITICALCVSS 9.8EG 9.82019-11-26
Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed to test for chunk offsets smaller than the beginning of the request did not work because of signed/…
- CVE-2018-8786CRITICALCVSS 9.8EG 9.82018-11-29
FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution.
- CVE-2016-3074CRITICALCVSS 9.8EG 9.82016-04-26
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buf…
- CVE-2022-43663CRITICALCVSS 8.1EG 9.82023-03-20
An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a buffer overflow. An attacker can send a malicious packet to t…
- CVE-2022-36025CRITICALCVSS 9.1EG 9.12022-09-24
Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect Conversion between Numeric Types. An error in 32 bit signed and unsigned types in the calculation of available gas in …
- CVE-2026-77412HIGHCVSS 8.9EG 8.92026-09-16
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-array field with type tag x into a signed int32 and passes the value directly to make when allocating the field buffer. A…
- CVE-2022-34169HIGHCVSS 7.5EG 8.92022-07-19
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java by…
- CVE-2026-26178HIGHCVSS 8.8EG 8.82026-04-14
Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-21693HIGHCVSS 8.8EG 8.82026-01-07
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in …
- CVE-2026-21688HIGHCVSS 8.8EG 8.82026-01-07
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in …
- CVE-2024-49093HIGHCVSS 8.8EG 8.82024-12-12
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
- CVE-2024-26162HIGHCVSS 8.8EG 8.82024-03-12
Microsoft ODBC Driver Remote Code Execution Vulnerability
- CVE-2023-5184HIGHCVSS 8.8EG 8.82023-09-27
Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the Zephyr IPM drivers.
- CVE-2023-24884HIGHCVSS 8.8EG 8.82023-04-11
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-23388HIGHCVSS 8.8EG 8.82023-03-14
Windows Bluetooth Driver Elevation of Privilege Vulnerability
- CVE-2021-21861HIGHCVSS 8.8EG 8.82021-08-16
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. When processing the 'hdlr' FOURCC code, a specially crafted MPEG-4 input can cause an i…
- CVE-2021-21860HIGHCVSS 8.8EG 8.82021-08-16
An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a…
- CVE-2021-23997HIGHCVSS 8.8EG 8.82021-06-24
Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox…
- CVE-2020-12417HIGHCVSS 8.8EG 8.82020-07-09
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulne…
- CVE-2009-0231HIGHCVSS 8.8EG 8.82009-07-15
The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted na…
- CVE-2026-55768HIGHCVSS 8.7EG 8.72026-07-30
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-…
- CVE-2026-4931HIGHCVSS 8.6EG 8.62026-04-07
Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible asset cost.
- CVE-2023-20006HIGHCVSS 7.5EG 8.62023-06-28
A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauth…
- CVE-2025-53733HIGHCVSS 8.4EG 8.42025-08-12
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2021-27478HIGHCVSS 8.2EG 8.22022-05-12
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may cause a denial-of-service condition.
- CVE-2020-2908HIGHCVSS 8.2EG 8.22020-04-15
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability allows high privil…
- CVE-2026-69438HIGHCVSS 8.1EG 8.12026-09-08
Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.
- CVE-2020-1913HIGHCVSS 8.1EG 8.12020-09-09
An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potential RCE via crafted JavaScript. Note that…
- CVE-2020-6096HIGHCVSS 8.1EG 8.12020-04-01
An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter …
- CVE-2018-10887HIGHCVSS 8.1EG 8.12018-07-10
A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bound read, allowing t…
- CVE-2026-47508HIGHCVSS 7.8EG 7.82026-09-30
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an incorrect conversion between numeric types. A successful exploit of this vulnerability might lead to code execut…
- CVE-2026-82457HIGHCVSS 7.8EG 7.82026-08-29
su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that trunca…
- CVE-2026-21069HIGHCVSS 7.8EG 7.82026-08-10
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
- CVE-2026-55123HIGHCVSS 7.8EG 7.82026-07-14
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- CVE-2026-50402HIGHCVSS 7.8EG 7.82026-07-14
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-45258HIGHCVSS 7.8EG 7.82026-06-27
dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition could overflow, so that a large offset and length wrapped around and passed the check. Th…
- CVE-2026-53133HIGHCVSS 7.8EG 7.82026-06-25
In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for block sizes >= 4G When the iommu is used the linearization of the mapping can give a single block that is very large split across multiple …
- CVE-2026-24192HIGHCVSS 7.8EG 7.82026-05-26
NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of ser…
- CVE-2026-24856HIGHCVSS 7.8EG 7.82026-01-28
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Versions prior to 2.3.1.2 have an undefined behavior issue when floating-point NaN values are conv…
- CVE-2026-21673HIGHCVSS 7.8EG 7.82026-01-06
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have overflows and underflows in CIccXmlArrayType::ParseTextCountNum(). This vulnerability affects users of the iccDEV l…
- CVE-2025-24059HIGHCVSS 7.8EG 7.82025-03-11
Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- CVE-2023-29346HIGHCVSS 7.8EG 7.82023-06-14
NTFS Elevation of Privilege Vulnerability
- CVE-2023-23401HIGHCVSS 7.8EG 7.82023-03-14
Windows Media Remote Code Execution Vulnerability
Map vulnerabilities like CWE-681 to your infrastructure
EchelonGraph correlates every CVE — across CWE-681 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →