CWE-681

High likelihood

Incorrect Conversion between Numeric Types

Parent: CWE-704 - Incorrect Type Conversion or Cast

When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.

116 vulnerabilities with CWE-681
CVE-2021-27478 HIGH
EIPStackGroup OpENer EtherNet/IP <Feb 10, 2021 - DoS
CVSS 8.2
CVE-2021-32996 HIGH
FANUC R-30iA/R-30iB - Memory Corruption
CVSS 7.5
CVE-2021-0964 MEDIUM
Android -10, -11, -12, -9 - Buffer Overflow
CVSS 6.5
CVE-2021-41272 HIGH
Besu 21.10.0-21.10.1 - Incorrect Conversion between Numeric Types in SHL/SHR/SAR Operations
CVSS 7.5
CVE-2021-41202 MEDIUM
TensorFlow 2.4.0-2.4.3, 2.6.0 - Integer Overflow via tf.range Kernel
CVSS 5.5
CVE-2021-36357 CRITICAL
OpenPOWER skiboot - Incorrect Conversion between Numeric Types in unpack_timestamp
CVSS 9.8
CVE-2021-21861 HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow via MPEG-4 hdlr FOURCC Handling
CVSS 8.8
CVE-2021-21860 HIGH
GPAC 1.0.1 - Heap-Based Buffer Overflow via MPEG-4 'trik' FOURCC Parsing
CVSS 8.8
CVE-2021-37679 HIGH
TensorFlow 2.3.0-2.3.3 - Information Disclosure via RaggedTensor Conversion
CVSS 7.1
CVE-2021-37669 MEDIUM
TensorFlow 2.3.0-2.3.3 - Denial of Service via Integer Overflow in NonMaxSuppressionV5
CVSS 5.5
CVE-2021-37661 MEDIUM
TensorFlow 2.3.0-2.3.3 - Denial of Service via Negative Argument in boosted_trees_create_quantile_stream_resource
CVSS 5.5
CVE-2021-37646 MEDIUM
TensorFlow 2.3.0-2.3.3 - Integer Overflow via StringNGrams Op
CVSS 5.5
CVE-2021-37645 MEDIUM
TensorFlow 2.3.0-2.3.3 and 2.4.0-2.4.2 - Integer Overflow in QuantizeAndDequantizeV4Grad
CVSS 5.5
CVE-2021-38187 CRITICAL
anymap < 0.12.1 - Type Confusion via Pointer Conversion
CVSS 9.8
CVE-2021-32461 HIGH
Trend Micro Password Manager < 5.0.0.1217 - Privilege Escalation via Integer Truncation
CVSS 7.8
CVE-2021-23997 HIGH
Firefox < 88.0 - Use-After-Free via Font Cache Data Type Conversion
CVSS 8.8
CVE-2021-32629 HIGH
Cranelift x64 <0.73 - Sandbox Escape
CVSS 7.2
CVE-2021-29539 LOW
TensorFlow < 2.1.4 - Denial of Service via ImmutableConst dtype Handling
CVSS 2.5
CVE-2021-3444 HIGH
Linux Kernel < 5.4.101 - Information Disclosure and Potential Code Execution via BPF Verifier Truncation
CVSS 7.8
CVE-2021-27219 HIGH
GNOME GLib <2.66.6, <2.67.3 - Memory Corruption
CVSS 7.5
CVE-2021-27218 HIGH
GNOME GLib <2.66.7 & <2.67.4 - Info Disclosure
CVSS 7.5
CVE-2020-28588 MEDIUM
Linux Kernel 5.1-5.10 - Information Disclosure via /proc/pid/syscall
CVSS 5.5
CVE-2020-15225 HIGH
django-filter < 2.4.0 - Denial of Service via NumberFilter Exponential Input
CVSS 7.5
CVE-2020-13545 HIGH
SoftMaker Office 2021 - Memory Corruption
CVSS 7.8
CVE-2020-13544 HIGH
SoftMaker Office 2021 - Buffer Overflow
CVSS 7.8
Details
Vulnerabilities 116
Exploit Likelihood High