CWE-681
133 CVEs • Abstraction: Base • Likelihood of Exploit: High
Incorrect Conversion between Numeric Types
When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.
CVEs (133)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2. |
1Qualcomm 12Apq8096au Firmware Msm8996au FirmwareQca6574au Firmware+9 moreJun 17, 2026 Apr 16, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 While handling the vendor command there is an integer truncation issue that could yield a buffer overflow due to int data type copied to u8 data type in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronic...Show more |
2Opensuse Oracle2Leap Vm VirtualboxJun 17, 2026 Apr 15, 2020 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Easily exploitable vulnerability...Show more |
3Debian FedoraprojectGnu3Debian Linux FedoraGlibcJun 17, 2026 Apr 1, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for t...Show more |
2Fedoraproject Nagios2Fedora Remote Plug In ExecutorJun 17, 2026 Mar 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call. |
uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a heap buffer and a subsequent crash. It can be triggered with an HTTP POST request to...Show more |
In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation and denial of service. |
In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument is int32. In this case data_size and num_segments fields are truncated from int64 to int32 and can...Show more |
4Netapp OracleSiemens+1 more5Cloud Backup Mysql WorkbenchOntap Select Deploy Administration Utility+2 moreJun 17, 2026 Dec 5, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact. |
2Canonical Module Signature Project2Module Signature Ubuntu LinuxNov 21, 2024 Nov 29, 2019 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors. |
Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed to test for chunk offsets smaller than the beginning of the request did not work...Show more |
1Powerdns 1Authoritative Server Jun 17, 2026 Nov 22, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a serial between 2^31 and 2^32-1 while trying to notify a slave leads to DoS. |
GNU Serveez through 0.2.2 has an Information Leak. An attacker may send an HTTP POST request to the /cgi-bin/reader URI. The attacker must include a Content-length header with a large positive value that, when represente...Show more |
2Gnu Netapp4Binutils Binutils GoldHci Management Node+1 moreJun 17, 2026 Jul 23, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread...Show more |
An issue was discovered in the MQTT input plugin in Fluent Bit through 1.0.4. When this plugin acts as an MQTT broker (server), it mishandles incoming network messages. After processing a crafted packet, the plugin's mqt...Show more |
5Canonical DebianFedoraproject+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreJun 17, 2026 Feb 3, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have un...Show more |
5Canonical DebianFedoraproject+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreJun 17, 2026 Nov 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code exec...Show more |
1Atlantiswordprocessor 1Atlantis Word Processor Nov 21, 2024 Oct 1, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable stack-based buffer overflow vulnerability exists in the JPEG parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted image embedded within a document can cause a length to be miscalculated...Show more |
Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)S...Show more |
2Debian Libgit22Debian Linux Libgit2Nov 21, 2024 Jul 10, 2018 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn leads to an out of bou...Show more |