VYPR

CWE-197

Numeric Truncation Error

BaseIncompleteLikelihood: Low

Description

Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.

When a primitive is cast to a smaller primitive, the high order bits of the large value are lost in the conversion, potentially resulting in an unexpected value that is not equal to the original value. This value may be required as an index into a buffer, a loop iterator, or simply necessary state data. In any case, the value cannot be trusted and the system will be in an undefined state. While this method may be employed viably to isolate the low bits of a value, this usage is rare, and truncation usually implies that an implementation error has occurred.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (61)

page 3 of 4
  • CVE-2026-62883MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62881MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62769MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2024-21429MedMar 12, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows USB Hub Driver Remote Code Execution Vulnerability

  • CVE-2026-6679HigJun 25, 2026
    risk 0.42cvss 7.5epss 0.01

    A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when computing the length of the ACK record-number list, causing an undersized buffer to be allocated and…

  • CVE-2026-42944HigMay 20, 2026
    risk 0.42cvss 7.5epss 0.01

    NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses'…

  • CVE-2024-38086MedJul 9, 2024
    risk 0.42cvss 6.4epss 0.01

    Azure Kinect SDK Remote Code Execution Vulnerability

  • CVE-2023-36641MedNov 14, 2023
    risk 0.42cvss 6.5epss 0.01

    A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1, all versions, FortiProxy 1.0 all versions, FortiOS version 7.4.0, FortiOS version…

  • CVE-2026-40380MedMay 12, 2026
    risk 0.40cvss 6.2epss 0.00

    Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.

  • CVE-2024-21377MedFeb 13, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows DNS Information Disclosure Vulnerability

  • CVE-2022-34680MedDec 30, 2022
    risk 0.36cvss 5.5epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of service.

  • CVE-2026-6039MedJun 15, 2026
    risk 0.35cvss epss 0.00

    LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count taken from the file was truncated to a 16-bit value when the point buffer was sized, while the full count was used to fill it, so…

  • CVE-2026-32240MedMar 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be truncated to a 64-bit integer. In theory, this bug could enable HTTP…

  • CVE-2025-10543MedDec 2, 2025
    risk 0.27cvss 5.3epss 0.00

    In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds 65535 bytes. This may lead to unexpected content in packets sent to the server (for example, part of an…

  • CVE-2026-42371MedApr 27, 2026
    risk 0.26cvss 5.1epss 0.00

    uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.

  • CVE-2026-44927LowMay 8, 2026
    risk 0.12cvss 2.9epss 0.00

    In uriparser before 1.0.2, there is pointer difference truncation to int in various places.

  • CVE-2026-56650HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55142MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  • CVE-2026-50357HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

  • CVE-2026-50332HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.