VYPR

CWE-197

Numeric Truncation Error

BaseIncompleteLikelihood: Low

Description

Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.

When a primitive is cast to a smaller primitive, the high order bits of the large value are lost in the conversion, potentially resulting in an unexpected value that is not equal to the original value. This value may be required as an index into a buffer, a loop iterator, or simply necessary state data. In any case, the value cannot be trusted and the system will be in an undefined state. While this method may be employed viably to isolate the low bits of a value, this usage is rare, and truncation usually implies that an implementation error has occurred.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (79)

page 1 of 4
  • CVE-2022-42475CriKEVJan 2, 2023
    risk 0.90cvss 9.8epss 0.99

    A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated…

  • CVE-2024-43639CriNov 12, 2024
    risk 0.64cvss 9.8epss 0.09

    Windows KDC Proxy Remote Code Execution Vulnerability

  • CVE-2026-87529CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.01

    Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78512HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

  • CVE-2024-49018HigNov 12, 2024
    risk 0.57cvss 8.8epss 0.02

    SQL Server Native Client Remote Code Execution Vulnerability

  • CVE-2024-43519HigOct 8, 2024
    risk 0.57cvss 8.8epss 0.01

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-30009HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2023-32143HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link DAP-1360 webupg UPGCGI_CheckAuth Numeric Truncation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this…

  • CVE-2024-28944HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-21451HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver Remote Code Execution Vulnerability

  • CVE-2024-21440HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver Remote Code Execution Vulnerability

  • CVE-2024-21391HigFeb 13, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-21352HigFeb 13, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-29050HigApr 9, 2024
    risk 0.55cvss 8.4epss 0.01

    Windows Cryptographic Services Remote Code Execution Vulnerability

  • CVE-2026-69512HigSep 8, 2026
    risk 0.52cvss 8.0epss 0.01

    Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-68880HigSep 8, 2026
    risk 0.52cvss 8.0epss 0.01

    Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-6965HigJul 15, 2025
    risk 0.52cvss 7.7epss 0.73

    There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

  • CVE-2024-21310HigJan 9, 2024
    risk 0.52cvss 7.8epss 0.12

    Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

  • CVE-2020-15202CriSep 25, 2020
    risk 0.52cvss 9.0epss 0.01

    In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking two `int64` (i.e., `long long`) arguments. However, there are several places in TensorFlow where a lambda taking `int` or `int32`…

  • CVE-2026-69822HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.