CWE-681 · 90 записей
Incorrect Conversion between Numeric Types
CVE этого класса
90 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
54В плане | CVE-2022-34169Proof of concept | Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheetsapache · xalan-java · CWE-681 | Высокая7,5 | — | 81,0 % | 19 июл. 2022 г. |
50В плане | CVE-2016-3074Proof of concept | Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or libgd · libgd · CWE-681 | Критическая9,8 | — | 37,2 % | 26 апр. 2016 г. |
46В плане | CVE-2009-0231Эксплойта нет | The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and Smicrosoft · windows 2000 · CWE-681 | Высокая8,8 | — | 37,5 % | 15 июл. 2009 г. |
40В плане | CVE-2019-19317Эксплойта нет | lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to casqlite · sqlite · CWE-681 | Критическая9,8 | — | 4,3 % | 5 дек. 2019 г. |
40В плане | CVE-2019-14842Эксплойта нет | Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks.redhat · libnbd · CWE-681 | Критическая9,8 | — | 1,8 % | 26 нояб. 2019 г. |
39Наблюдать | CVE-2021-38187Эксплойта нет | An issue was discovered in the anymap crate through 0.12.1 for Rust.anymap project · anymap · CWE-681 | Критическая9,8 | — | 1,4 % | 8 авг. 2021 г. |
39Наблюдать | CVE-2021-36357Эксплойта нет | An issue was discovered in OpenPOWER 2.6 firmware.openpowerfoundation · skiboot · CWE-681 | Критическая9,8 | — | 1,2 % | 22 окт. 2021 г. |
39Наблюдать | CVE-2022-40138Эксплойта нет | An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used tofacebook · hermes · CWE-681 | Критическая9,8 | — | 1,0 % | 10 окт. 2022 г. |
37Наблюдать | CVE-2008-1721Proof of concept | Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a nepython · python · CWE-681 | Высокая7,5 | — | 22,6 % | 10 апр. 2008 г. |
36Наблюдать | CVE-2017-7308Готовый эксплойт | The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size datalinux · linux kernel · CWE-681 | Высокая7,8 | — | 17,8 % | 29 мар. 2017 г. |
36Наблюдать | CVE-2024-26162Эксплойта нет | Microsoft ODBC Driver Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-681 | Высокая8,8 | — | 2,0 % | 12 мар. 2024 г. |
35Наблюдать | CVE-2023-24884Эксплойта нет | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-681 | Высокая8,8 | — | 1,6 % | 11 апр. 2023 г. |
35Наблюдать | CVE-2023-23388Proof of concept | Windows Bluetooth Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-681 | Высокая8,8 | — | 1,6 % | 14 мар. 2023 г. |
35Наблюдать | CVE-2024-49093Эксплойта нет | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerabilitymicrosoft · windows 11 24h2 · CWE-681 | Высокая8,8 | — | 0,9 % | 11 дек. 2024 г. |
35Наблюдать | CVE-2021-23997Эксплойта нет | Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache.mozilla · firefox · CWE-681 | Высокая8,8 | — | 0,8 % | 24 июн. 2021 г. |
35Наблюдать | CVE-2026-77412Эксплойта нет | RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Clientrabbitmq · amqp091-go · CWE-681 | Высокая8,9 | — | 0,5 % | 16 сент. 2026 г. |
34Наблюдать | CVE-2008-3282Эксплойта нет | Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, apache · openoffice · CWE-681 | Высокая7,8 | — | 10,8 % | 29 авг. 2008 г. |
34Наблюдать | CVE-2026-55768Эксплойта нет | GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame length causes a remote pre-authentication denial of serviceallinurl · goaccess · CWE-681 | Высокая8,7 | — | 0,5 % | 30 июл. 2026 г. |
34Наблюдать | CVE-2026-4931Эксплойта нет | Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible asset cost.marginal · v1-core · CWE-681 | Высокая8,6 | — | 0,5 % | 7 апр. 2026 г. |
34Наблюдать | CVE-2026-82457Эксплойта нет | su-exec through 0.3 Privilege Escalation via Numeric User IDncopa · su-exec · CWE-681 | Высокая8,5 | — | 0,2 % | 29 авг. 2026 г. |
33Наблюдать | CVE-2023-46848Эксплойта нет | Squid: denial of service in ftpsquid-cache · squid · CWE-681 | Высокая7,5 | — | 10,2 % | 3 нояб. 2023 г. |
33Наблюдать | CVE-2025-53733Эксплойта нет | Microsoft Word Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-681 | Высокая8,4 | — | 0,5 % | 12 авг. 2025 г. |
32Наблюдать | CVE-2007-4988Эксплойта нет | Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary codeimagemagick · imagemagick · CWE-681 | Высокая7,8 | — | 3,1 % | 24 сент. 2007 г. |
32Наблюдать | CVE-2026-69438Эксплойта нет | Microsoft JScript Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-681 | Высокая8,1 | — | 0,7 % | 8 сент. 2026 г. |
31Наблюдать | CVE-2020-6582Эксплойта нет | Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number nagios · remote plug in executor · CWE-681 | Высокая7,5 | — | 4,4 % | 16 мар. 2020 г. |
- CVE-2022-3416954В плане
Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
ВысокаяCVSS 7,5Proof of conceptEPSS 81 %apache · xalan-java19 июл. 2022 г.
- CVE-2016-307450В плане
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or
КритическаяCVSS 9,8Proof of conceptEPSS 37 %libgd · libgd26 апр. 2016 г.
- CVE-2009-023146В плане
The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and S
ВысокаяCVSS 8,8Эксплойта нетEPSS 37 %microsoft · windows 200015 июл. 2009 г.
- CVE-2019-1931740В плане
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to ca
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %sqlite · sqlite5 дек. 2019 г.
- CVE-2019-1484240В плане
Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %redhat · libnbd26 нояб. 2019 г.
- CVE-2021-3818739Наблюдать
An issue was discovered in the anymap crate through 0.12.1 for Rust.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %anymap project · anymap8 авг. 2021 г.
- CVE-2021-3635739Наблюдать
An issue was discovered in OpenPOWER 2.6 firmware.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openpowerfoundation · skiboot22 окт. 2021 г.
- CVE-2022-4013839Наблюдать
An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %facebook · hermes10 окт. 2022 г.
- CVE-2008-172137Наблюдать
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a ne
ВысокаяCVSS 7,5Proof of conceptEPSS 23 %python · python10 апр. 2008 г.
- CVE-2017-730836Наблюдать
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data
ВысокаяCVSS 7,8Готовый эксплойтEPSS 18 %linux · linux kernel29 мар. 2017 г.
- CVE-2024-2616236Наблюдать
Microsoft ODBC Driver Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %microsoft · windows 10 150712 мар. 2024 г.
- CVE-2023-2488435Наблюдать
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %microsoft · windows 10 150711 апр. 2023 г.
- CVE-2023-2338835Наблюдать
Windows Bluetooth Driver Elevation of Privilege Vulnerability
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %microsoft · windows 10 150714 мар. 2023 г.
- CVE-2024-4909335Наблюдать
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · windows 11 24h211 дек. 2024 г.
- CVE-2021-2399735Наблюдать
Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mozilla · firefox24 июн. 2021 г.
- CVE-2026-7741235Наблюдать
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client
ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %rabbitmq · amqp091-go16 сент. 2026 г.
- CVE-2008-328234Наблюдать
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1,
ВысокаяCVSS 7,8Эксплойта нетEPSS 11 %apache · openoffice29 авг. 2008 г.
- CVE-2026-5576834Наблюдать
GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame length causes a remote pre-authentication denial of service
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %allinurl · goaccess30 июл. 2026 г.
- CVE-2026-493134Наблюдать
Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible asset cost.
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %marginal · v1-core7 апр. 2026 г.
- CVE-2026-8245734Наблюдать
su-exec through 0.3 Privilege Escalation via Numeric User ID
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %ncopa · su-exec29 авг. 2026 г.
- CVE-2023-4684833Наблюдать
Squid: denial of service in ftp
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %squid-cache · squid3 нояб. 2023 г.
- CVE-2025-5373333Наблюдать
Microsoft Word Remote Code Execution Vulnerability
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %microsoft · 365 apps12 авг. 2025 г.
- CVE-2007-498832Наблюдать
Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %imagemagick · imagemagick24 сент. 2007 г.
- CVE-2026-6943832Наблюдать
Microsoft JScript Remote Code Execution Vulnerability
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %microsoft · windows 10 16078 сент. 2026 г.
- CVE-2020-658231Наблюдать
Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %nagios · remote plug in executor16 мар. 2020 г.