CWE-681
123 CVEs • Abstraction: Base • Likelihood of Exploit: High
Incorrect Conversion between Numeric Types
When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.
CVEs (123)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusio...Show more |
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusio...Show more |
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have overflows and underflows in CIccXmlArrayType::ParseTextCountNum(). This vulnerability affects us...Show more |
In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds 65535 bytes. This may lead to unexpected content...Show more |
CoreDNS is a DNS server that chains plugins. Starting in version 1.2.0 and prior to version 1.12.4, the CoreDNS etcd plugin contains a TTL confusion vulnerability where lease IDs are incorrectly used as TTL values, enabl...Show more |
1Microsoft 6365 Apps OfficeOffice Long Term Servicing Channel+3 moreJun 17, 2026 Aug 12, 2025 N/A· v4 8.4 HIGH· v3 N/A· v2 Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Mar 11, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
1Microsoft 2Windows 11 24h2 Windows Server 2025Jun 17, 2026 Dec 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versions up to, and including, 1.5.6. This is due to a numerical logic flaw when transferring funds to an...Show more |
1Microsoft 5Windows Server 2012 Windows Server 2016Windows Server 2019+2 moreJun 17, 2026 Jul 9, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 DHCP Server Service Remote Code Execution Vulnerability |
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to version 0.4.0b1, when looping over a `range` of the form `range(start, start + N)`, if `start` is negat...Show more |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Mar 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft ODBC Driver Remote Code Execution Vulnerability |
2Debian Mozilla3Debian Linux FirefoxThunderbirdJun 17, 2026 Feb 20, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115....Show more |
1Dell 291Alienware M15 R6 Firmware Alienware M15 R7 FirmwareChengming 3900 Firmware+288 moreJun 17, 2026 Feb 6, 2024 N/A· v4 4.4 MEDIUM· v3 N/A· v2
Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.
|
2Redhat Squid Cache5Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+2 moreJun 17, 2026 Nov 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input. |
Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the Zephyr IPM drivers. |
GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class...Show more |
1Cisco 2Adaptive Security Appliance Software Firepower Threat DefenseJun 17, 2026 Jun 28, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances co...Show more |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Jun 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 NTFS Elevation of Privilege Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Apr 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability |