CWE-704 · 197 записей
Incorrect Type Conversion or Cast
CVE этого класса
197 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
54В плане | CVE-2025-41646Proof of concept | RevPi Webstatus application is vulnerable to an authentication bypasskunbus · revpi status · CWE-704 | Критическая9,8 | — | 51,5 % | 6 июн. 2025 г. |
43В плане | CVE-2017-5115Эксплойта нет | Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to potentially exploit object corruption vgoogle · chrome · CWE-704 | Высокая8,8 | — | 26,3 % | 27 окт. 2017 г. |
43В плане | CVE-2018-15981Эксплойта нет | Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability.adobe · flash player desktop runtime · CWE-704 | Критическая9,8 | — | 11,7 % | 29 нояб. 2018 г. |
42В плане | CVE-2017-3106Proof of concept | Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files.adobe · flash player desktop runtime · CWE-704 | Высокая8,8 | — | 22,3 % | 11 авг. 2017 г. |
42В плане | CVE-2018-4944Эксплойта нет | Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability.adobe · flash player · CWE-704 | Критическая9,8 | — | 8,6 % | 19 мая 2018 г. |
42В плане | CVE-2018-12812Эксплойта нет | Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions have a Type Confusiadobe · acrobat dc · CWE-704 | Критическая9,8 | — | 8,6 % | 20 июл. 2018 г. |
42В плане | CVE-2015-3120Эксплойта нет | Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIRadobe · flash player · CWE-704 | Критическая10,0 | — | 7,4 % | 9 июл. 2015 г. |
41В плане | CVE-2018-3843Эксплойта нет | An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotatifoxitsoftware · foxit reader · CWE-704 | Высокая8,8 | — | 21,6 % | 19 апр. 2018 г. |
41В плане | CVE-2021-28918Proof of concept | Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indetenetmask project · netmask · CWE-704 | Критическая9,1 | — | 16,7 % | 1 апр. 2021 г. |
41В плане | CVE-2016-7398Эксплойта нет | A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earliephp · ext-http · CWE-704 | Критическая9,8 | — | 6,8 % | 6 сент. 2019 г. |
41В плане | CVE-2016-7979Эксплойта нет | Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code bartifex · ghostscript · CWE-704 | Критическая9,8 | — | 6,4 % | 23 мая 2017 г. |
40В плане | CVE-2018-5007Эксплойта нет | Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability.adobe · flash player desktop runtime · CWE-704 | Высокая8,8 | — | 17,8 % | 20 июл. 2018 г. |
40В плане | CVE-2018-12794Эксплойта нет | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Type Confusiadobe · acrobat dc · CWE-704 | Высокая8,8 | — | 15,7 % | 20 июл. 2018 г. |
40В плане | CVE-2026-15826Proof of concept | User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parametercozmoslabs · user profile builder – beautiful user registration forms, user profiles & user role editor · CWE-704 | Критическая9,8 | — | 3,9 % | 15 авг. 2026 г. |
40В плане | CVE-2018-14403Эксплойта нет | MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for assotechsmith · mp4v2 · CWE-704 | Критическая9,8 | — | 2,6 % | 19 июл. 2018 г. |
40В плане | CVE-2021-33318Эксплойта нет | An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1ipmatcher project · ipmatcher · CWE-704 | Критическая9,8 | — | 2,0 % | 16 мая 2022 г. |
40В плане | CVE-2017-9183Эксплойта нет | libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7.autotrace project · autotrace · CWE-704 | Критическая9,8 | — | 1,9 % | 23 мая 2017 г. |
39Наблюдать | CVE-2020-6151Эксплойта нет | A memory corruption vulnerability exists in the TIFF handle_COMPRESSION_PACKBITS functionality of Accusoft ImageGear 19.7.accusoft · imagegear · CWE-704 | Критическая9,8 | — | 1,6 % | 1 сент. 2020 г. |
39Наблюдать | CVE-2020-25576Эксплойта нет | An issue was discovered in the rand_core crate before 0.4.2 for Rust.rust-random · rand · CWE-704 | Критическая9,8 | — | 1,6 % | 14 сент. 2020 г. |
39Наблюдать | CVE-2011-1460Эксплойта нет | WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.google · blink · CWE-704 | Критическая9,8 | — | 0,9 % | 5 нояб. 2019 г. |
39Наблюдать | CVE-2011-2337Эксплойта нет | A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.google · blink · CWE-704 | Критическая9,8 | — | 0,8 % | 7 нояб. 2019 г. |
39Наблюдать | CVE-2025-41648Эксплойта нет | Pilz: Authentication Bypass in IndustrialPI Webstatuspilz · industrialpi 4 with industrialpi webstatus · CWE-704 | Критическая9,8 | — | 0,8 % | 1 июл. 2025 г. |
39Наблюдать | CVE-2023-6249Эксплойта нет | ipm: signed to unsigned conversion problem in esp32_ipm_sendzephyrproject · zephyr · CWE-704 | Критическая9,8 | — | 0,4 % | 18 февр. 2024 г. |
39Наблюдать | CVE-2026-58822Эксплойта нет | In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting.google · android · CWE-704 | Критическая9,8 | — | 0,4 % | 8 сент. 2026 г. |
38Наблюдать | CVE-2018-4953Эксплойта нет | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Type Confusiadobe · acrobat dc · CWE-704 | Высокая8,8 | — | 9,3 % | 9 июл. 2018 г. |
- CVE-2025-4164654В плане
RevPi Webstatus application is vulnerable to an authentication bypass
КритическаяCVSS 9,8Proof of conceptEPSS 52 %kunbus · revpi status6 июн. 2025 г.
- CVE-2017-511543В плане
Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to potentially exploit object corruption v
ВысокаяCVSS 8,8Эксплойта нетEPSS 26 %google · chrome27 окт. 2017 г.
- CVE-2018-1598143В плане
Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %adobe · flash player desktop runtime29 нояб. 2018 г.
- CVE-2017-310642В плане
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files.
ВысокаяCVSS 8,8Proof of conceptEPSS 22 %adobe · flash player desktop runtime11 авг. 2017 г.
- CVE-2018-494442В плане
Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %adobe · flash player19 мая 2018 г.
- CVE-2018-1281242В плане
Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions have a Type Confusi
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %adobe · acrobat dc20 июл. 2018 г.
- CVE-2015-312042В плане
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %adobe · flash player9 июл. 2015 г.
- CVE-2018-384341В плане
An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049 parses files with associated file annotati
ВысокаяCVSS 8,8Эксплойта нетEPSS 22 %foxitsoftware · foxit reader19 апр. 2018 г.
- CVE-2021-2891841В плане
Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indete
КритическаяCVSS 9,1Proof of conceptEPSS 17 %netmask project · netmask1 апр. 2021 г.
- CVE-2016-739841В плане
A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlie
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %php · ext-http6 сент. 2019 г.
- CVE-2016-797941В плане
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code b
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %artifex · ghostscript23 мая 2017 г.
- CVE-2018-500740В плане
Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability.
ВысокаяCVSS 8,8Эксплойта нетEPSS 18 %adobe · flash player desktop runtime20 июл. 2018 г.
- CVE-2018-1279440В плане
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Type Confusi
ВысокаяCVSS 8,8Эксплойта нетEPSS 16 %adobe · acrobat dc20 июл. 2018 г.
- CVE-2026-1582640В плане
User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
КритическаяCVSS 9,8Proof of conceptEPSS 4 %cozmoslabs · user profile builder – beautiful user registration forms, user profiles & user role editor15 авг. 2026 г.
- CVE-2018-1440340В плане
MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for asso
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %techsmith · mp4v219 июл. 2018 г.
- CVE-2021-3331840В плане
An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ipmatcher project · ipmatcher16 мая 2022 г.
- CVE-2017-918340В плане
libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %autotrace project · autotrace23 мая 2017 г.
- CVE-2020-615139Наблюдать
A memory corruption vulnerability exists in the TIFF handle_COMPRESSION_PACKBITS functionality of Accusoft ImageGear 19.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %accusoft · imagegear1 сент. 2020 г.
- CVE-2020-2557639Наблюдать
An issue was discovered in the rand_core crate before 0.4.2 for Rust.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %rust-random · rand14 сент. 2020 г.
- CVE-2011-146039Наблюдать
WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %google · blink5 нояб. 2019 г.
- CVE-2011-233739Наблюдать
A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %google · blink7 нояб. 2019 г.
- CVE-2025-4164839Наблюдать
Pilz: Authentication Bypass in IndustrialPI Webstatus
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pilz · industrialpi 4 with industrialpi webstatus1 июл. 2025 г.
- CVE-2023-624939Наблюдать
ipm: signed to unsigned conversion problem in esp32_ipm_send
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %zephyrproject · zephyr18 февр. 2024 г.
- CVE-2026-5882239Наблюдать
In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %google · android8 сент. 2026 г.
- CVE-2018-495338Наблюдать
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Type Confusi
ВысокаяCVSS 8,8Эксплойта нетEPSS 9 %adobe · acrobat dc9 июл. 2018 г.