VYPR

CWE-704

Incorrect Type Conversion or Cast

ClassIncomplete

Description

The product does not correctly convert an object, resource, or structure from one type to a different type.

Hierarchy (View 1000)

CVEs mapped to this weakness (295)

page 11 of 15
  • CVE-2021-29424HigApr 6, 2021
    risk 0.49cvss 7.5epss 0.02

    The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

  • CVE-2020-35864HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the flatbuffers crate through 2020-04-11 for Rust. read_scalar (and read_scalar_at) can transmute values without unsafe blocks.

  • CVE-2017-13888HigJan 11, 2019
    risk 0.49cvss 7.5epss 0.01

    In iOS before 11.2, a type confusion issue was addressed with improved memory handling.

  • CVE-2018-8076HigMar 15, 2018
    risk 0.49cvss 7.5epss 0.01

    ZenMate 1.5.4 for macOS suffers from a type confusion vulnerability within the com.zenmate.chron-xpc LaunchDaemon component. The LaunchDaemon implements an XPC service that uses an insecure XPC API for accessing data from an inbound XPC message. This could potentially result in…

  • CVE-2018-19019HigJan 22, 2019
    risk 0.48cvss 7.3epss 0.01

    A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.

  • CVE-2025-22044HigApr 16, 2025
    risk 0.46cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: fix narrowing conversion in acpi_nfit_ctl Syzkaller has reported a warning in to_nfit_bus_uuid(): "only secondary bus families can be translated". This warning is emited if the argument is equal to…

  • CVE-2022-41668HigNov 4, 2022
    risk 0.46cvss 7.0epss 0.00

    A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal…

  • CVE-2022-41828HigSep 29, 2022
    risk 0.46cvss 8.1epss 0.02

    In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name.

  • CVE-2017-0607HigMay 12, 2017
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…

  • CVE-2025-54429MedJul 28, 2025
    risk 0.45cvss —epss 0.00

    Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. There are various account address types in Frontier, e.g. precompiled contracts, smart contracts, and externally owned accounts. Some EVM mechanisms should be unreachable by certain types of…

  • CVE-2023-21627MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Trusted Execution Environment while calling service API with invalid address.

  • CVE-2023-21638MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.

  • CVE-2022-33240MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Audio due to incorrect type cast during audio use-cases.

  • CVE-2022-33301MedApr 13, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to incorrect type conversion or cast in audio while using audio playback/capture when crafted address is sent from AGM IPC to AGM.

  • CVE-2022-25715MedJan 9, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in display driver due to incorrect type casting while accessing the fence structure fields

  • CVE-2022-21786MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In audio DSP, there is a possible memory corruption due to improper casting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558822; Issue ID: ALPS06558822.

  • CVE-2014-9627HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.01

    The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other…

  • CVE-2018-12793MedJul 20, 2018
    risk 0.43cvss 6.5epss 0.09

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

  • CVE-2026-48140MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.00

    There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigger invalid enum states and undefined behavior, potentially resulting in a denial of service. Successful exploitation requires an attacker to supply a specially…

  • CVE-2026-45685HigJun 2, 2026
    risk 0.42cvss 7.5epss 0.00

    OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to…