CWE-681

High likelihood

Incorrect Conversion between Numeric Types

Parent: CWE-704 - Incorrect Type Conversion or Cast

When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.

124 vulnerabilities with CWE-681
CVE-2019-16200 HIGH
GNU Serveez <0.2.2 - Info Disclosure
CVSS 7.5
CVE-2019-1010204 MEDIUM
GNU binutils 2.21-2.31.1 and binutils_gold 1.11-1.16 - Denial of Service via Invalid ELF e_shoff Header
CVSS 5.5
CVE-2019-9749 HIGH
Fluent Bit <1.0.4 - Memory Corruption
CVSS 7.5
CVE-2019-7310 HIGH
Poppler 0.73.0 - Heap-Based Buffer Over-Read via XRef::getEntry Integer Signedness Error
CVSS 7.8
CVE-2018-8786 CRITICAL
FreeRDP <2.0.0-rc4 - Memory Corruption
CVSS 9.8
CVE-2018-3999 HIGH
Atlantis Word Processor 3.2.5.0 - Stack-Based Buffer Overflow in JPEG Parser
CVSS 7.8
CVE-2018-1000224 HIGH
Godot Engine < 2.1.5 and 3.0 < 3.0.6 - Denial of Service via Malformed Network Packet
CVSS 7.5
CVE-2018-10887 HIGH
libgit2 < 0.27.3 - Integer Overflow and Out-of-Bounds Read in git_delta_apply
CVSS 8.1
CVE-2018-5711 MEDIUM
GD Graphics Library <7.2.1 - Buffer Overflow
CVSS 5.5
CVE-2018-5251 MEDIUM
libming 0.4.8 - Denial of Service via Crafted SWF File
CVSS 6.5
CVE-2017-17446 MEDIUM
Game_Music_Emu 0.6.1 - Denial of Service via Negative Size in Mem_File_Reader::read_avail
CVSS 6.5
CVE-2017-0857 HIGH
Android 7.0 7.1.1 7.1.2 8.0 - Denial of Service via Divide By Zero
CVSS 7.5
CVE-2017-12140 MEDIUM
ImageMagick 7.0.6-1 - Memory Corruption
CVSS 6.5
CVE-2017-7308 HIGH
AF_PACKET packet_set_ring Privilege Escalation
CVSS 7.8
CVE-2016-3074 CRITICAL
libgd 2.1.1 - Denial of Service and Potential Remote Code Execution via Crafted Compressed GD2 Data
CVSS 9.8
CVE-2015-3406 HIGH
Module::Signature <0.74 - Code Injection
CVSS 7.5
CVE-2014-125012 MEDIUM
FFmpeg 2.0 - Integer Coercion Error
CVSS 5.3
CVE-2014-125011 MEDIUM
FFmpeg 2.0 - Integer Coercion Error
CVSS 5.3
CVE-2010-2807
FreeType <2.4.2 - DoS/Code Injection
CVE-2009-0231 HIGH
Microsoft Windows - Remote Code Execution via Crafted EOT Font Name Table
CVSS 8.8
CVE-2008-3282 HIGH
OpenOffice.org 2.4.1 - Denial of Service via Integer Overflow in Memory Allocator
CVSS 7.8
CVE-2008-1721
Python < 2.4.6 - Remote Code Execution via Integer Signedness Error in zlib Extension
CVE-2007-4268 HIGH
Apple Mac OS X 10.4-10.4.10 - Local Arbitrary Code Execution via AppleTalk Message
CVSS 7.8
CVE-2007-4988 HIGH
ImageMagick < 6.3.5-9 - Remote Code Execution via Crafted DIB Image Width
CVSS 7.8
Details
Vulnerabilities 124
Exploit Likelihood High