İçeriğe atla
Noroxi

CWE-681 · 88 kayıt

Incorrect Conversion between Numeric Types

Bu sınıftaki CVE’ler

88 kayıt

  • CVE-2022-34169
    54Planlayın

    Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets

    YüksekCVSS 7,5Kavram kanıtıEPSS %81

    apache · xalan-java19 Tem 2022

  • CVE-2016-3074
    50Planlayın

    Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or

    KritikCVSS 9,8Kavram kanıtıEPSS %37

    libgd · libgd26 Nis 2016

  • CVE-2009-0231
    46Planlayın

    The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and S

    YüksekCVSS 8,8İstismar yokEPSS %37

    microsoft · windows 200015 Tem 2009

  • CVE-2019-19317
    40Planlayın

    lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to ca

    KritikCVSS 9,8İstismar yokEPSS %4

    sqlite · sqlite5 Ara 2019

  • CVE-2019-14842
    40Planlayın

    Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks.

    KritikCVSS 9,8İstismar yokEPSS %2

    redhat · libnbd26 Kas 2019

  • CVE-2021-38187
    39İzleyin

    An issue was discovered in the anymap crate through 0.12.1 for Rust.

    KritikCVSS 9,8İstismar yokEPSS %1

    anymap project · anymap8 Ağu 2021

  • CVE-2021-36357
    39İzleyin

    An issue was discovered in OpenPOWER 2.6 firmware.

    KritikCVSS 9,8İstismar yokEPSS %1

    openpowerfoundation · skiboot22 Eki 2021

  • CVE-2022-40138
    39İzleyin

    An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to

    KritikCVSS 9,8İstismar yokEPSS %1

    facebook · hermes10 Eki 2022

  • CVE-2008-1721
    37İzleyin

    Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a ne

    YüksekCVSS 7,5Kavram kanıtıEPSS %23

    python · python10 Nis 2008

  • CVE-2017-7308
    36İzleyin

    The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data

    YüksekCVSS 7,8SilahlaştırılmışEPSS %18

    linux · linux kernel29 Mar 2017

  • CVE-2024-26162
    36İzleyin

    Microsoft ODBC Driver Remote Code Execution Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %2

    microsoft · windows 10 150712 Mar 2024

  • CVE-2023-24884
    35İzleyin

    Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %2

    microsoft · windows 10 150711 Nis 2023

  • CVE-2023-23388
    35İzleyin

    Windows Bluetooth Driver Elevation of Privilege Vulnerability

    YüksekCVSS 8,8Kavram kanıtıEPSS %2

    microsoft · windows 10 150714 Mar 2023

  • CVE-2024-49093
    35İzleyin

    Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    microsoft · windows 11 24h211 Ara 2024

  • CVE-2021-23997
    35İzleyin

    Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache.

    YüksekCVSS 8,8İstismar yokEPSS %1

    mozilla · firefox24 Haz 2021

  • CVE-2026-77412
    35İzleyin

    RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client

    YüksekCVSS 8,9İstismar yokEPSS %1

    rabbitmq · amqp091-go16 Eyl 2026

  • CVE-2008-3282
    34İzleyin

    Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1,

    YüksekCVSS 7,8İstismar yokEPSS %11

    apache · openoffice29 Ağu 2008

  • CVE-2026-55768
    34İzleyin

    GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame length causes a remote pre-authentication denial of service

    YüksekCVSS 8,7İstismar yokEPSS %0

    allinurl · goaccess30 Tem 2026

  • CVE-2026-4931
    34İzleyin

    Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible asset cost.

    YüksekCVSS 8,6İstismar yokEPSS %0

    marginal · v1-core7 Nis 2026

  • CVE-2026-82457
    34İzleyin

    su-exec through 0.3 Privilege Escalation via Numeric User ID

    YüksekCVSS 8,5İstismar yokEPSS %0

    ncopa · su-exec29 Ağu 2026

  • CVE-2023-46848
    33İzleyin

    Squid: denial of service in ftp

    YüksekCVSS 7,5İstismar yokEPSS %10

    squid-cache · squid3 Kas 2023

  • CVE-2025-53733
    33İzleyin

    Microsoft Word Remote Code Execution Vulnerability

    YüksekCVSS 8,4İstismar yokEPSS %1

    microsoft · 365 apps12 Ağu 2025

  • CVE-2007-4988
    32İzleyin

    Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code

    YüksekCVSS 7,8İstismar yokEPSS %3

    imagemagick · imagemagick24 Eyl 2007

  • CVE-2026-69438
    32İzleyin

    Microsoft JScript Remote Code Execution Vulnerability

    YüksekCVSS 8,1İstismar yokEPSS %1

    microsoft · windows 10 16078 Eyl 2026

  • CVE-2020-6582
    31İzleyin

    Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number

    YüksekCVSS 7,5İstismar yokEPSS %4

    nagios · remote plug in executor16 Mar 2020

Tüm zafiyet sınıfları