CWE-681
133 CVEs • Abstraction: Base • Likelihood of Exploit: High
Incorrect Conversion between Numeric Types
When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.
CVEs (133)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxJun 17, 2026 Jan 16, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a cra...Show more |
2Debian Libming2Debian Linux LibmingNov 21, 2024 Jan 5, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value) in the readSBits function (util/read.c). Remote attackers can leverage this vulnerability to cause a denial of service...Show more |
1Game Music Emu Project 1Game Music Emu May 13, 2026 Dec 6, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Mem_File_Reader::read_avail function in Data_Reader.cpp in the Game_Music_Emu library (aka game-music-emu) 0.6.1 does not ensure a non-negative size, which allows remote attackers to cause a denial of service (applic...Show more |
Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-65122447. |
The ReadDCMImage function in coders\dcm.c in ImageMagick 7.0.6-1 has an integer signedness error leading to excessive memory consumption via a crafted DCM file. |
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness erro...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLibgd+3 moreMay 6, 2026 Apr 26, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which trigge...Show more |
3Apple CanonicalFreetype5Freetype Iphone OsMac Os X+2 moreApr 29, 2026 Aug 19, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 FreeType before 2.4.2 uses incorrect integer data types during bounds checking, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file. |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Jul 15, 2009 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary co...Show more |
2Apache Fedoraproject2Fedora OpenofficeApr 23, 2026 Aug 29, 2008 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (appli...Show more |
3Canonical DebianPython3Debian Linux PythonUbuntu LinuxApr 23, 2026 Apr 10, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffe...Show more |
Integer signedness error in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk message with a negative value, which satisfies a signed com...Show more |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxApr 23, 2026 Sep 24, 2007 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow...Show more |