CWE-197
Numeric Truncation Error
Description
Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (61)
page 1 of 4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-42475 | Cri | 0.90 | 9.8 | 0.99 | KEV | Jan 2, 2023 | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated… | |
| CVE-2024-43639 | Cri | 0.64 | 9.8 | 0.09 | Nov 12, 2024 | Windows KDC Proxy Remote Code Execution Vulnerability | ||
| CVE-2024-49018 | Hig | 0.57 | 8.8 | 0.02 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-43519 | Hig | 0.57 | 8.8 | 0.01 | Oct 8, 2024 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-30009 | Hig | 0.57 | 8.8 | 0.02 | May 14, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2023-32143 | Hig | 0.57 | 8.8 | 0.01 | May 3, 2024 | D-Link DAP-1360 webupg UPGCGI_CheckAuth Numeric Truncation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this… | ||
| CVE-2024-28944 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-21451 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Microsoft ODBC Driver Remote Code Execution Vulnerability | ||
| CVE-2024-21440 | Hig | 0.57 | 8.8 | 0.02 | Mar 12, 2024 | Microsoft ODBC Driver Remote Code Execution Vulnerability | ||
| CVE-2024-21391 | Hig | 0.57 | 8.8 | 0.02 | Feb 13, 2024 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-21352 | Hig | 0.57 | 8.8 | 0.02 | Feb 13, 2024 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-29050 | Hig | 0.55 | 8.4 | 0.01 | Apr 9, 2024 | Windows Cryptographic Services Remote Code Execution Vulnerability | ||
| CVE-2025-6965 | Hig | 0.52 | 7.7 | 0.75 | Jul 15, 2025 | There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. | ||
| CVE-2024-21310 | Hig | 0.52 | 7.8 | 0.12 | Jan 9, 2024 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | ||
| CVE-2020-15202 | Cri | 0.52 | 9.0 | 0.01 | Sep 25, 2020 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking two `int64` (i.e., `long long`) arguments. However, there are several places in TensorFlow where a lambda taking `int` or `int32`… | ||
| CVE-2026-68804 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-63525 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-62739 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62698 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-44823 | Hig | 0.51 | 7.8 | 0.00 | Jun 9, 2026 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
- risk 0.90cvss 9.8epss 0.99
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated…
- risk 0.64cvss 9.8epss 0.09
Windows KDC Proxy Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
D-Link DAP-1360 webupg UPGCGI_CheckAuth Numeric Truncation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this…
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- risk 0.55cvss 8.4epss 0.01
Windows Cryptographic Services Remote Code Execution Vulnerability
- risk 0.52cvss 7.7epss 0.75
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
- risk 0.52cvss 7.8epss 0.12
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- risk 0.52cvss 9.0epss 0.01
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking two `int64` (i.e., `long long`) arguments. However, there are several places in TensorFlow where a lambda taking `int` or `int32`…
- risk 0.51cvss 7.8epss 0.00
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.