CWE-197
Numeric Truncation Error
Description
Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (79)
page 4 of 4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21377 | Med | 0.36 | 5.5 | 0.01 | Feb 13, 2024 | Windows DNS Information Disclosure Vulnerability | ||
| CVE-2022-34680 | Med | 0.36 | 5.5 | 0.00 | Dec 30, 2022 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of service. | ||
| CVE-2026-6039 | Med | 0.35 | — | 0.00 | Jun 15, 2026 | LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count taken from the file was truncated to a 16-bit value when the point buffer was sized, while the full count was used to fill it, so… | ||
| CVE-2026-32240 | Med | 0.35 | 6.5 | 0.00 | Mar 12, 2026 | Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be truncated to a 64-bit integer. In theory, this bug could enable HTTP… | ||
| CVE-2026-77014 | Med | 0.34 | 5.3 | 0.00 | Aug 20, 2026 | A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of… | ||
| CVE-2026-86315 | Med | 0.33 | 6.2 | 0.00 | Sep 7, 2026 | An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry… | ||
| CVE-2026-76151 | Med | 0.30 | — | 0.01 | Sep 16, 2026 | Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (application crash) via an excessively large… | ||
| CVE-2025-10543 | Med | 0.27 | 5.3 | 0.00 | Dec 2, 2025 | In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds 65535 bytes. This may lead to unexpected content in packets sent to the server (for example, part of an… | ||
| CVE-2026-42371 | Med | 0.26 | 5.1 | 0.00 | Apr 27, 2026 | uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes. | ||
| CVE-2026-80213 | Med | 0.19 | 4.0 | 0.00 | Aug 27, 2026 | An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its range. A label longer than 255 octets had its length stored modulo 256 but the label data was written unchanged, and… | ||
| CVE-2026-63449 | Low | 0.17 | 3.7 | 0.00 | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SIP parser in rust/src/sip/parser.rs stores request and response body lengths in 16-bit fields. A SIP body larger than 65,536 bytes… | ||
| CVE-2026-65610 | Low | 0.16 | — | 0.00 | Aug 19, 2026 | nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influence the victim's execution environment can provide an arbitrary HOME path with length that is truncated to 0. The expression (homelen - 1) is promoted to… | ||
| CVE-2026-49263 | Low | 0.13 | — | 0.00 | Aug 14, 2026 | Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large but well-formed `br_table` instruction, the WASM… | ||
| CVE-2026-44927 | Low | 0.12 | 2.9 | 0.00 | May 8, 2026 | In uriparser before 1.0.2, there is pointer difference truncation to int in various places. | ||
| CVE-2026-56650 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-55142 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-50357 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. | ||
| CVE-2026-50332 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49792 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. |
- risk 0.36cvss 5.5epss 0.01
Windows DNS Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of service.
- risk 0.35cvss —epss 0.00
LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count taken from the file was truncated to a 16-bit value when the point buffer was sized, while the full count was used to fill it, so…
- risk 0.35cvss 6.5epss 0.00
Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be truncated to a 64-bit integer. In theory, this bug could enable HTTP…
- risk 0.34cvss 5.3epss 0.00
A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of…
- risk 0.33cvss 6.2epss 0.00
An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry…
- risk 0.30cvss —epss 0.01
Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (application crash) via an excessively large…
- risk 0.27cvss 5.3epss 0.00
In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds 65535 bytes. This may lead to unexpected content in packets sent to the server (for example, part of an…
- risk 0.26cvss 5.1epss 0.00
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
- risk 0.19cvss 4.0epss 0.00
An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its range. A label longer than 255 octets had its length stored modulo 256 but the label data was written unchanged, and…
- risk 0.17cvss 3.7epss 0.00
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SIP parser in rust/src/sip/parser.rs stores request and response body lengths in 16-bit fields. A SIP body larger than 65,536 bytes…
- risk 0.16cvss —epss 0.00
nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influence the victim's execution environment can provide an arbitrary HOME path with length that is truncated to 0. The expression (homelen - 1) is promoted to…
- risk 0.13cvss —epss 0.00
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large but well-formed `br_table` instruction, the WASM…
- risk 0.12cvss 2.9epss 0.00
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.01
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.