CWE-704 · 197 kayıt
Incorrect Type Conversion or Cast
Bu sınıftaki CVE’ler
197 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
54Planlayın | CVE-2025-41646Kavram kanıtı | RevPi Webstatus application is vulnerable to an authentication bypasskunbus · revpi status · CWE-704 | Kritik9,8 | — | %51,5 | 6 Haz 2025 |
43Planlayın | CVE-2017-5115İstismar yok | Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to potentially exploit object corruption vgoogle · chrome · CWE-704 | Yüksek8,8 | — | %26,3 | 27 Eki 2017 |
43Planlayın | CVE-2018-15981İstismar yok | Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability.adobe · flash player desktop runtime · CWE-704 | Kritik9,8 | — | %11,7 | 29 Kas 2018 |
42Planlayın | CVE-2017-3106Kavram kanıtı | Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files.adobe · flash player desktop runtime · CWE-704 | Yüksek8,8 | — | %22,3 | 11 Ağu 2017 |
42Planlayın | CVE-2018-4944İstismar yok | Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability.adobe · flash player · CWE-704 | Kritik9,8 | — | %8,6 | 19 May 2018 |
42Planlayın | CVE-2018-12812İstismar yok | Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions have a Type Confusiadobe · acrobat dc · CWE-704 | Kritik9,8 | — | %8,6 | 20 Tem 2018 |
42Planlayın | CVE-2015-3120İstismar yok | Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIRadobe · flash player · CWE-704 | Kritik10,0 | — | %7,4 | 9 Tem 2015 |
41Planlayın | CVE-2018-3843İstismar yok | An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotatifoxitsoftware · foxit reader · CWE-704 | Yüksek8,8 | — | %21,6 | 19 Nis 2018 |
41Planlayın | CVE-2021-28918Kavram kanıtı | Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indetenetmask project · netmask · CWE-704 | Kritik9,1 | — | %16,7 | 1 Nis 2021 |
41Planlayın | CVE-2016-7398İstismar yok | A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earliephp · ext-http · CWE-704 | Kritik9,8 | — | %6,8 | 6 Eyl 2019 |
41Planlayın | CVE-2016-7979İstismar yok | Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code bartifex · ghostscript · CWE-704 | Kritik9,8 | — | %6,4 | 23 May 2017 |
40Planlayın | CVE-2018-5007İstismar yok | Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability.adobe · flash player desktop runtime · CWE-704 | Yüksek8,8 | — | %17,8 | 20 Tem 2018 |
40Planlayın | CVE-2018-12794İstismar yok | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Type Confusiadobe · acrobat dc · CWE-704 | Yüksek8,8 | — | %15,7 | 20 Tem 2018 |
40Planlayın | CVE-2026-15826Kavram kanıtı | User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parametercozmoslabs · user profile builder – beautiful user registration forms, user profiles & user role editor · CWE-704 | Kritik9,8 | — | %3,9 | 15 Ağu 2026 |
40Planlayın | CVE-2018-14403İstismar yok | MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for assotechsmith · mp4v2 · CWE-704 | Kritik9,8 | — | %2,6 | 19 Tem 2018 |
40Planlayın | CVE-2021-33318İstismar yok | An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1ipmatcher project · ipmatcher · CWE-704 | Kritik9,8 | — | %2,0 | 16 May 2022 |
40Planlayın | CVE-2017-9183İstismar yok | libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7.autotrace project · autotrace · CWE-704 | Kritik9,8 | — | %1,9 | 23 May 2017 |
39İzleyin | CVE-2020-6151İstismar yok | A memory corruption vulnerability exists in the TIFF handle_COMPRESSION_PACKBITS functionality of Accusoft ImageGear 19.7.accusoft · imagegear · CWE-704 | Kritik9,8 | — | %1,6 | 1 Eyl 2020 |
39İzleyin | CVE-2020-25576İstismar yok | An issue was discovered in the rand_core crate before 0.4.2 for Rust.rust-random · rand · CWE-704 | Kritik9,8 | — | %1,6 | 14 Eyl 2020 |
39İzleyin | CVE-2011-1460İstismar yok | WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.google · blink · CWE-704 | Kritik9,8 | — | %0,9 | 5 Kas 2019 |
39İzleyin | CVE-2011-2337İstismar yok | A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.google · blink · CWE-704 | Kritik9,8 | — | %0,8 | 7 Kas 2019 |
39İzleyin | CVE-2025-41648İstismar yok | Pilz: Authentication Bypass in IndustrialPI Webstatuspilz · industrialpi 4 with industrialpi webstatus · CWE-704 | Kritik9,8 | — | %0,8 | 1 Tem 2025 |
39İzleyin | CVE-2023-6249İstismar yok | ipm: signed to unsigned conversion problem in esp32_ipm_sendzephyrproject · zephyr · CWE-704 | Kritik9,8 | — | %0,4 | 18 Şub 2024 |
39İzleyin | CVE-2026-58822İstismar yok | In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting.google · android · CWE-704 | Kritik9,8 | — | %0,4 | 8 Eyl 2026 |
38İzleyin | CVE-2018-4953İstismar yok | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Type Confusiadobe · acrobat dc · CWE-704 | Yüksek8,8 | — | %9,3 | 9 Tem 2018 |
- CVE-2025-4164654Planlayın
RevPi Webstatus application is vulnerable to an authentication bypass
KritikCVSS 9,8Kavram kanıtıEPSS %52kunbus · revpi status6 Haz 2025
- CVE-2017-511543Planlayın
Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to potentially exploit object corruption v
YüksekCVSS 8,8İstismar yokEPSS %26google · chrome27 Eki 2017
- CVE-2018-1598143Planlayın
Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability.
KritikCVSS 9,8İstismar yokEPSS %12adobe · flash player desktop runtime29 Kas 2018
- CVE-2017-310642Planlayın
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files.
YüksekCVSS 8,8Kavram kanıtıEPSS %22adobe · flash player desktop runtime11 Ağu 2017
- CVE-2018-494442Planlayın
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability.
KritikCVSS 9,8İstismar yokEPSS %9adobe · flash player19 May 2018
- CVE-2018-1281242Planlayın
Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions have a Type Confusi
KritikCVSS 9,8İstismar yokEPSS %9adobe · acrobat dc20 Tem 2018
- CVE-2015-312042Planlayın
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR
KritikCVSS 10,0İstismar yokEPSS %7adobe · flash player9 Tem 2015
- CVE-2018-384341Planlayın
An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotati
YüksekCVSS 8,8İstismar yokEPSS %22foxitsoftware · foxit reader19 Nis 2018
- CVE-2021-2891841Planlayın
Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indete
KritikCVSS 9,1Kavram kanıtıEPSS %17netmask project · netmask1 Nis 2021
- CVE-2016-739841Planlayın
A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlie
KritikCVSS 9,8İstismar yokEPSS %7php · ext-http6 Eyl 2019
- CVE-2016-797941Planlayın
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code b
KritikCVSS 9,8İstismar yokEPSS %6artifex · ghostscript23 May 2017
- CVE-2018-500740Planlayın
Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability.
YüksekCVSS 8,8İstismar yokEPSS %18adobe · flash player desktop runtime20 Tem 2018
- CVE-2018-1279440Planlayın
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Type Confusi
YüksekCVSS 8,8İstismar yokEPSS %16adobe · acrobat dc20 Tem 2018
- CVE-2026-1582640Planlayın
User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
KritikCVSS 9,8Kavram kanıtıEPSS %4cozmoslabs · user profile builder – beautiful user registration forms, user profiles & user role editor15 Ağu 2026
- CVE-2018-1440340Planlayın
MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for asso
KritikCVSS 9,8İstismar yokEPSS %3techsmith · mp4v219 Tem 2018
- CVE-2021-3331840Planlayın
An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1
KritikCVSS 9,8İstismar yokEPSS %2ipmatcher project · ipmatcher16 May 2022
- CVE-2017-918340Planlayın
libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7.
KritikCVSS 9,8İstismar yokEPSS %2autotrace project · autotrace23 May 2017
- CVE-2020-615139İzleyin
A memory corruption vulnerability exists in the TIFF handle_COMPRESSION_PACKBITS functionality of Accusoft ImageGear 19.7.
KritikCVSS 9,8İstismar yokEPSS %2accusoft · imagegear1 Eyl 2020
- CVE-2020-2557639İzleyin
An issue was discovered in the rand_core crate before 0.4.2 for Rust.
KritikCVSS 9,8İstismar yokEPSS %2rust-random · rand14 Eyl 2020
- CVE-2011-146039İzleyin
WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.
KritikCVSS 9,8İstismar yokEPSS %1google · blink5 Kas 2019
- CVE-2011-233739İzleyin
A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.
KritikCVSS 9,8İstismar yokEPSS %1google · blink7 Kas 2019
- CVE-2025-4164839İzleyin
Pilz: Authentication Bypass in IndustrialPI Webstatus
KritikCVSS 9,8İstismar yokEPSS %1pilz · industrialpi 4 with industrialpi webstatus1 Tem 2025
- CVE-2023-624939İzleyin
ipm: signed to unsigned conversion problem in esp32_ipm_send
KritikCVSS 9,8İstismar yokEPSS %0zephyrproject · zephyr18 Şub 2024
- CVE-2026-5882239İzleyin
In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting.
KritikCVSS 9,8İstismar yokEPSS %0google · android8 Eyl 2026
- CVE-2018-495338İzleyin
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Type Confusi
YüksekCVSS 8,8İstismar yokEPSS %9adobe · acrobat dc9 Tem 2018