CWE-704— Incorrect Type Conversion or Cast
The product does not correctly convert an object, resource, or structure from one type to a different type.— MITRE CWE catalog
299 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-704page 5 of 6
- CVE-2017-5717HIGHCVSS 7.8EG 7.82017-12-12
Type Confusion in Content Protection HECI Service in Intel Graphics Driver allows unprivileged user to elevate privileges via local access.
- CVE-2017-8159HIGHCVSS 7.8EG 7.82017-11-22
Some Huawei smartphones with software AGS-L09C233B019,AGS-W09C233B019,KOB-L09C233B017,KOB-W09C233B012 have a type confusion vulnerability. The program initializes a variable using one type, but it later accesses that variable using a type …
- CVE-2017-9042HIGHCVSS 7.8EG 7.82017-05-18
readelf.c in GNU Binutils 2017-04-12 has a "cannot be represented in type long" issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file.
- CVE-2016-8602HIGHCVSS 7.8EG 7.82017-04-14
The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Postscript document that calls .sethalftone5 with…
- CVE-2016-7655HIGHCVSS 7.8EG 7.82017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "CoreMedia External Displays" component. It allows local users to gain privileges or cause a denial of…
- CVE-2016-7617HIGHCVSS 7.8EG 7.82017-02-20
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (type con…
- CVE-2017-2962HIGHCVSS 7.8EG 7.82017-01-11
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable type confusion vulnerability in the XSLT engine related to localization functionality. Successful exploitation could …
- CVE-2016-4710HIGHCVSS 7.8EG 7.82016-09-25
WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4709.
- CVE-2016-4709HIGHCVSS 7.8EG 7.82016-09-25
WindowServer in Apple OS X before 10.12 allows local users to obtain root access via vectors that leverage "type confusion," a different vulnerability than CVE-2016-4710.
- CVE-2022-41668HIGHCVSS 7.0EG 7.82022-11-04
A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicious code. Affected P…
- CVE-2022-33301HIGHCVSS 6.7EG 7.82023-04-13
Memory corruption due to incorrect type conversion or cast in audio while using audio playback/capture when crafted address is sent from AGM IPC to AGM.
- CVE-2022-25715HIGHCVSS 6.7EG 7.82023-01-09
Memory corruption in display driver due to incorrect type casting while accessing the fence structure fields
- CVE-2025-51678HIGHCVSS 7.5EG 7.52026-07-17
An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to unexpected behavior.
- CVE-2026-59871HIGHCVSS 7.5EG 7.52026-07-08
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.p…
- CVE-2026-46597HIGHCVSS 7.5EG 7.52026-05-22
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
- CVE-2026-45685HIGHCVSS 7.5EG 7.52026-05-18
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowi…
- CVE-2026-40613HIGHCVSS 7.5EG 7.52026-04-21
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing functions in coturn perform unsafe pointer casts from uint8_t * to uint16_t * without alignment checks. When processing a…
- CVE-2024-47181HIGHCVSS 7.5EG 7.52024-11-27
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An unaligned memory access can be triggered in the two RPL implementations of the Contiki-NG operating system. The problem can occur when either one of these RP…
- CVE-2024-39590HIGHCVSS 7.5EG 7.52024-09-18
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of servic…
- CVE-2024-39589HIGHCVSS 7.5EG 7.52024-09-18
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of servic…
- CVE-2024-28130HIGHCVSS 7.5EG 7.52024-04-23
An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS DCMTK 3.6.8. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a maliciou…
- CVE-2023-33101HIGHCVSS 7.5EG 7.52024-04-01
Transient DOS while processing DL NAS TRANSPORT message with payload length 0.
- CVE-2020-10735HIGHCVSS 7.5EG 7.52022-09-09
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.f…
- CVE-2022-25852HIGHCVSS 7.5EG 7.52022-06-17
All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:*…
- CVE-2022-1642HIGHCVSS 7.5EG 7.52022-06-16
A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a …
- CVE-2021-30300HIGHCVSS 7.5EG 7.52022-01-13
Possible denial of service due to incorrectly decoding hex data for the SIB2 OTA message and assigning a garbage value to choice when processing the SRS configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdra…
- CVE-2021-39989HIGHCVSS 7.5EG 7.52022-01-03
The HwNearbyMain module has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability may cause a process to restart.
- CVE-2021-29424HIGHCVSS 7.5EG 7.52021-04-06
The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP address…
- CVE-2021-29662HIGHCVSS 7.5EG 7.52021-03-31
The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP ad…
- CVE-2018-5817HIGHCVSS 7.5EG 7.52019-02-20
A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_common.cpp) can be exploited to trigger an infinite loop.
- CVE-2017-13888HIGHCVSS 7.5EG 7.52019-01-11
In iOS before 11.2, a type confusion issue was addressed with improved memory handling.
- CVE-2018-12453HIGHCVSS 7.5EG 7.52018-06-16
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream.
- CVE-2018-8076HIGHCVSS 7.5EG 7.52018-03-15
ZenMate 1.5.4 for macOS suffers from a type confusion vulnerability within the com.zenmate.chron-xpc LaunchDaemon component. The LaunchDaemon implements an XPC service that uses an insecure XPC API for accessing data from an inbound XPC me…
- CVE-2015-5219HIGHCVSS 7.5EG 7.52017-07-21
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
- CVE-2026-55076HIGHCVSS 7.4EG 7.42026-07-06
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP…
- CVE-2018-19019HIGHCVSS 7.3EG 7.32019-01-22
A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
- CVE-2026-34379HIGHCVSS 7.1EG 7.12026-04-06
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists i…
- CVE-2026-25503HIGHCVSS 7.1EG 7.12026-02-03
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, type confusion allowed malformed ICC profiles to trigger undefined behav…
- CVE-2017-0607HIGHCVSS 7.0EG 7.02017-05-12
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2025-54429MEDIUMCVSS 6.9EG 6.92025-07-28
Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. There are various account address types in Frontier, e.g. precompiled contracts, smart contracts, and externally owned accounts. Some EVM mechanisms s…
- CVE-2011-3037MEDIUMCVSS v2 6.8EG 6.82012-03-05
Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the splitting of anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a craf…
- CVE-2011-3036MEDIUMCVSS v2 6.8EG 6.82012-03-05
Google Chrome before 17.0.963.65 does not properly perform a cast of an unspecified variable during handling of line boxes, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted docu…
- CVE-2011-1799MEDIUMCVSS v2 6.8EG 6.82011-05-16
Google Chrome before 11.0.696.68 does not properly perform casts of variables during interaction with the WebKit engine, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vecto…
- CVE-2011-1441MEDIUMCVSS v2 6.8EG 6.82011-05-03
Google Chrome before 11.0.696.57 does not properly perform a cast of an unspecified variable during handling of floating select lists, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a c…
- CVE-2011-1200MEDIUMCVSS v2 6.8EG 6.82011-03-11
Google Chrome before 10.0.648.127 does not properly perform a cast of an unspecified variable during text rendering, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
- CVE-2023-21627MEDIUMCVSS 6.7EG 6.72023-08-08
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
- CVE-2023-21638MEDIUMCVSS 6.7EG 6.72023-07-04
Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.
- CVE-2022-33240MEDIUMCVSS 6.7EG 6.72023-06-06
Memory corruption in Audio due to incorrect type cast during audio use-cases.
- CVE-2022-21786MEDIUMCVSS 6.7EG 6.72022-07-06
In audio DSP, there is a possible memory corruption due to improper casting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558822;…
- CVE-2026-105754MEDIUMCVSS 6.5EG 6.52026-10-05
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in the disaggregated scale-out path accepts caller-supplied tensors in the features.kwargs_data field, cache identifier…
Map vulnerabilities like CWE-704 to your infrastructure
EchelonGraph correlates every CVE — across CWE-704 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →