CWE-704— Incorrect Type Conversion or Cast
The product does not correctly convert an object, resource, or structure from one type to a different type.— MITRE CWE catalog
299 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-704page 1 of 6
- CVE-2017-0037CRITICALCVSS 8.1EG 9.0⚠ KEV2017-02-26
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary …
- CVE-2017-8291CRITICALCVSS 7.8EG 9.0⚠ KEV2017-04-27
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in t…
- CVE-2026-58822CRITICALCVSS 9.8EG 9.82026-09-08
In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-15826CRITICALCVSS 9.8EG 9.82026-08-15
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_ins…
- CVE-2025-41648CRITICALCVSS 9.8EG 9.82025-07-01
An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available settings of the IndustrialPI.
- CVE-2025-41646CRITICALCVSS 9.8EG 9.82025-06-06
An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device
- CVE-2024-5436CRITICALCVSS 9.8EG 9.82024-05-31
Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.
- CVE-2021-33318CRITICALCVSS 9.8EG 9.82022-05-16
An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1.3 and below (WatsonWebserver) due to insufficient validation of input IP addresses and netmasks ag…
- CVE-2021-38187CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the anymap crate through 0.12.1 for Rust. It violates soundness via conversion of a *u8 to a *u64.
- CVE-2020-35880CRITICALCVSS 9.8EG 9.82020-12-31
An issue was discovered in the bigint crate through 2020-05-07 for Rust. It allows a soundness violation.
- CVE-2020-25576CRITICALCVSS 9.8EG 9.82020-09-14
An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.
- CVE-2020-6151CRITICALCVSS 9.8EG 9.82020-09-01
A memory corruption vulnerability exists in the TIFF handle_COMPRESSION_PACKBITS functionality of Accusoft ImageGear 19.7. A specially crafted malformed file can cause a memory corruption. An attacker can provide a malicious file to trigge…
- CVE-2011-2337CRITICALCVSS 9.8EG 9.82019-11-07
A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.
- CVE-2011-1460CRITICALCVSS 9.8EG 9.82019-11-05
WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.
- CVE-2016-7398CRITICALCVSS 9.8EG 9.82019-09-06
A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbi…
- CVE-2019-2097CRITICALCVSS 9.8EG 9.82019-06-07
In HAliasAnalyzer.Query of hydrogen-alias-analysis.h, there is possible memory corruption due to type confusion. This could lead to remote code execution from a malicious proxy configuration, with no additional execution privileges needed.…
- CVE-2018-15981CRITICALCVSS 9.8EG 9.82018-11-29
Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2018-12812CRITICALCVSS 9.8EG 9.82018-07-20
Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of …
- CVE-2018-14403CRITICALCVSS 9.8EG 9.82018-07-19
MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of-bounds memory access.
- CVE-2018-4944CRITICALCVSS 9.8EG 9.82018-05-19
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
- CVE-2017-9183CRITICALCVSS 9.8EG 9.82017-05-23
libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7.
- CVE-2016-7979CRITICALCVSS 9.8EG 9.82017-05-23
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.
- CVE-2018-4920CRITICALCVSS 8.8EG 9.82018-05-19
Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
- CVE-2022-43663CRITICALCVSS 8.1EG 9.82023-03-20
An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a buffer overflow. An attacker can send a malicious packet to t…
- CVE-2022-3979CRITICALCVSS 5.6EG 9.82022-11-13
A vulnerability was found in NagVis up to 1.9.33 and classified as problematic. This issue affects the function checkAuthCookie of the file share/server/core/classes/CoreLogonMultisite.php. The manipulation of the argument hash leads to in…
- CVE-2010-20115CRITICALCVSS 9.3EG 9.32025-08-21
Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsi…
- CVE-2023-21651CRITICALCVSS 9.3EG 9.32023-08-08
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
- CVE-2026-27809CRITICALCVSS 9.1EG 9.12026-02-26
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past the expected row size), decode_rle() rais…
- CVE-2021-35942CRITICALCVSS 9.1EG 9.12021-07-22
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or discl…
- CVE-2021-28918CRITICALCVSS 9.1EG 9.12021-04-01
Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated atta…
- CVE-2025-40541CRITICALCVSS 7.2EG 9.12026-02-24
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. O…
- CVE-2025-40540CRITICALCVSS 7.2EG 9.12026-02-24
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deploymen…
- CVE-2025-40539CRITICALCVSS 7.2EG 9.12026-02-24
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deploymen…
- CVE-2026-28609HIGHCVSS 8.8EG 8.82026-09-08
In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-21692HIGHCVSS 8.8EG 8.82026-01-07
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in …
- CVE-2025-13720HIGHCVSS 8.8EG 8.82025-12-02
Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-62494HIGHCVSS 8.8EG 8.82025-10-16
A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. * The code first checks if the left-hand operand is a string. * It then attempts to convert the right-hand opera…
- CVE-2023-28162HIGHCVSS 8.8EG 8.82023-06-02
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird …
- CVE-2023-25737HIGHCVSS 8.8EG 8.82023-06-02
An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
- CVE-2021-43537HIGHCVSS 8.8EG 8.82021-12-08
An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- CVE-2021-39173HIGHCVSS 8.8EG 8.82021-08-27
Cachet is an open source status page system. Prior to version 2.5.1 authenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. Th…
- CVE-2020-16103HIGHCVSS 8.8EG 8.82020-12-14
Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior…
- CVE-2011-1805HIGHCVSS 8.8EG 8.82020-06-03
Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-7081HIGHCVSS 8.8EG 8.82020-04-17
A type confusion vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitary code read/write on the system running it.
- CVE-2019-10355HIGHCVSS 8.8EG 8.82019-07-31
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts.
- CVE-2018-6157HIGHCVSS 8.8EG 8.82019-06-27
Type confusion in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
- CVE-2018-4284HIGHCVSS 8.8EG 8.82019-04-03
A type confusion issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.
- CVE-2019-5757HIGHCVSS 8.8EG 8.82019-02-19
An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
- CVE-2018-17685HIGHCVSS 8.8EG 8.82019-01-24
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open …
- CVE-2018-6170HIGHCVSS 8.8EG 8.82019-01-09
A bad cast in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Map vulnerabilities like CWE-704 to your infrastructure
EchelonGraph correlates every CVE — across CWE-704 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →