CWE-681
123 CVEs • Abstraction: Base • Likelihood of Exploit: High
Incorrect Conversion between Numeric Types
When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.
CVEs (123)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where sign conversion issuescasting an unsigned primitive to signed may lead to denial of service or information disclosure. |
An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a buffer overflow. An attacker can send a ma...Show more |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Mar 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Media Remote Code Execution Vulnerability |
1Microsoft 11Windows 10 1507 Windows 10 1607Windows 10 1809+8 moreJun 17, 2026 Mar 14, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Bluetooth Driver Elevation of Privilege Vulnerability |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreJun 17, 2026 Jan 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Office Visio Remote Code Execution Vulnerability |
2Debian Nvidia4Cloud Gaming Debian LinuxGpu Display Driver+1 moreJun 17, 2026 Dec 30, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of service. |
2Debian Nvidia4Cloud Gaming Debian LinuxGpu Display Driver+1 moreJun 17, 2026 Dec 30, 2022 N/A· v4 7.1 HIGH· v3 N/A· v2 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tamperin...Show more |
2Debian Nvidia4Cloud Gaming Debian LinuxGpu Display Driver+1 moreJun 17, 2026 Dec 30, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause truncation errors when casting a primitive to a primitive of smaller size causes...Show more |
1Siemens 1Siplus Tim 1531 Irc Firmware Jun 17, 2026 Nov 10, 2022 6.9 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6GK7543-1MX00-0XE0) (All versions < V2.4.8). Casting an internal value could lead to floating point e...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 1, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Oxenstored 32->31 bit integer truncation issues Integers in Ocaml are 63 or 31 bits of signed precision. The Ocaml Xenbus library takes a C uint32_t out of the ring and casts it directly to an Ocaml integer. In 64-bit Oc...Show more |
An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and subsequently execute arbitrary code. Note...Show more |
Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect Conversion between Numeric Types. An error in 32 bit signed and unsigned types in the calculation o...Show more |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Sep 1, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does...Show more |
6Apache AzulDebian+3 more167 Mode Transition Tool Active Iq Unified ManagerCloud Insights Acquisition Unit+13 moreJun 17, 2026 Jul 19, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execut...Show more |
A vulnerability was found in FFmpeg 2.0. It has been classified as problematic. Affected is an unknown function of the file libavcodec/dxtroy.c. The manipulation leads to integer coercion error. It is possible to launch...Show more |
A vulnerability was found in FFmpeg 2.0. It has been declared as problematic. Affected by this vulnerability is the function decode_frame of the file libavcodec/ansi.c. The manipulation leads to integer coercion error. T...Show more |
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may cause a denial-of-service condition. |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 May 5, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when an Internet Content Adapt...Show more |
3Fedoraproject LinuxOracle5Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+2 moreJun 17, 2026 Mar 25, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is...Show more |
slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can preve...Show more |