Skip to content
Noroxi

CWE-704 · 197 records

Incorrect Type Conversion or Cast

CVEs in this class

197 records

  • RevPi Webstatus application is vulnerable to an authentication bypass

    CriticalCVSS 9.8Proof of conceptEPSS 52%

    kunbus · revpi statusJun 6, 2025

  • Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to potentially exploit object corruption v

    HighCVSS 8.8No exploitEPSS 26%

    google · chromeOct 27, 2017

  • Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability.

    CriticalCVSS 9.8No exploitEPSS 12%

    adobe · flash player desktop runtimeNov 29, 2018

  • Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files.

    HighCVSS 8.8Proof of conceptEPSS 22%

    adobe · flash player desktop runtimeAug 11, 2017

  • Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability.

    CriticalCVSS 9.8No exploitEPSS 9%

    adobe · flash playerMay 19, 2018

  • Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions have a Type Confusi

    CriticalCVSS 9.8No exploitEPSS 9%

    adobe · acrobat dcJul 20, 2018

  • Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR

    CriticalCVSS 10.0No exploitEPSS 7%

    adobe · flash playerJul 9, 2015

  • An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotati

    HighCVSS 8.8No exploitEPSS 22%

    foxitsoftware · foxit readerApr 19, 2018

  • Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indete

    CriticalCVSS 9.1Proof of conceptEPSS 17%

    netmask project · netmaskApr 1, 2021

  • A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlie

    CriticalCVSS 9.8No exploitEPSS 7%

    php · ext-httpSep 6, 2019

  • Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code b

    CriticalCVSS 9.8No exploitEPSS 6%

    artifex · ghostscriptMay 23, 2017

  • Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability.

    HighCVSS 8.8No exploitEPSS 18%

    adobe · flash player desktop runtimeJul 20, 2018

  • Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Type Confusi

    HighCVSS 8.8No exploitEPSS 16%

    adobe · acrobat dcJul 20, 2018

  • User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    cozmoslabs · user profile builder – beautiful user registration forms, user profiles & user role editorAug 15, 2026

  • MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for asso

    CriticalCVSS 9.8No exploitEPSS 3%

    techsmith · mp4v2Jul 19, 2018

  • An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1

    CriticalCVSS 9.8No exploitEPSS 2%

    ipmatcher project · ipmatcherMay 16, 2022

  • libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7.

    CriticalCVSS 9.8No exploitEPSS 2%

    autotrace project · autotraceMay 23, 2017

  • CVE-2020-6151
    39Monitor

    A memory corruption vulnerability exists in the TIFF handle_COMPRESSION_PACKBITS functionality of Accusoft ImageGear 19.7.

    CriticalCVSS 9.8No exploitEPSS 2%

    accusoft · imagegearSep 1, 2020

  • An issue was discovered in the rand_core crate before 0.4.2 for Rust.

    CriticalCVSS 9.8No exploitEPSS 2%

    rust-random · randSep 14, 2020

  • CVE-2011-1460
    39Monitor

    WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.

    CriticalCVSS 9.8No exploitEPSS 1%

    google · blinkNov 5, 2019

  • CVE-2011-2337
    39Monitor

    A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.

    CriticalCVSS 9.8No exploitEPSS 1%

    google · blinkNov 7, 2019

  • Pilz: Authentication Bypass in IndustrialPI Webstatus

    CriticalCVSS 9.8No exploitEPSS 1%

    pilz · industrialpi 4 with industrialpi webstatusJul 1, 2025

  • CVE-2023-6249
    39Monitor

    ipm: signed to unsigned conversion problem in esp32_ipm_send

    CriticalCVSS 9.8No exploitEPSS 0%

    zephyrproject · zephyrFeb 18, 2024

  • In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting.

    CriticalCVSS 9.8No exploitEPSS 0%

    google · androidSep 8, 2026

  • CVE-2018-4953
    38Monitor

    Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Type Confusi

    HighCVSS 8.8No exploitEPSS 9%

    adobe · acrobat dcJul 9, 2018

All vulnerability classes