VYPR

CWE-704

Incorrect Type Conversion or Cast

ClassIncomplete

Description

The product does not correctly convert an object, resource, or structure from one type to a different type.

Hierarchy (View 1000)

CVEs mapped to this weakness (285)

page 11 of 15
  • CVE-2025-22044HigApr 16, 2025
    risk 0.46cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: fix narrowing conversion in acpi_nfit_ctl Syzkaller has reported a warning in to_nfit_bus_uuid(): "only secondary bus families can be translated". This warning is emited if the argument is equal to…

  • CVE-2022-41668HigNov 4, 2022
    risk 0.46cvss 7.0epss 0.00

    A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal…

  • CVE-2022-41828HigSep 29, 2022
    risk 0.46cvss 8.1epss 0.02

    In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name.

  • CVE-2017-0607HigMay 12, 2017
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android.…

  • CVE-2025-54429MedJul 28, 2025
    risk 0.45cvss epss 0.00

    Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. There are various account address types in Frontier, e.g. precompiled contracts, smart contracts, and externally owned accounts. Some EVM mechanisms should be unreachable by certain types of…

  • CVE-2023-21627MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Trusted Execution Environment while calling service API with invalid address.

  • CVE-2023-21638MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.

  • CVE-2022-33240MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Audio due to incorrect type cast during audio use-cases.

  • CVE-2022-33301MedApr 13, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to incorrect type conversion or cast in audio while using audio playback/capture when crafted address is sent from AGM IPC to AGM.

  • CVE-2022-25715MedJan 9, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in display driver due to incorrect type casting while accessing the fence structure fields

  • CVE-2022-21786MedJul 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In audio DSP, there is a possible memory corruption due to improper casting. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558822; Issue ID: ALPS06558822.

  • CVE-2014-9627HigJan 24, 2020
    risk 0.44cvss 7.8epss 0.01

    The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other…

  • CVE-2018-12793MedJul 20, 2018
    risk 0.43cvss 6.5epss 0.09

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

  • CVE-2026-48140MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.00

    There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigger invalid enum states and undefined behavior, potentially resulting in a denial of service. Successful exploitation requires an attacker to supply a specially…

  • CVE-2026-45685HigJun 2, 2026
    risk 0.42cvss 7.5epss 0.00

    OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to…

  • CVE-2026-46597HigMay 22, 2026
    risk 0.42cvss 7.5epss 0.00

    An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

  • CVE-2023-7345MedMay 19, 2026
    risk 0.42cvss 6.5epss 0.00

    Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting incorrect hexadecimal field parsing when values contain an odd number of…

  • CVE-2026-40613HigApr 21, 2026
    risk 0.42cvss 7.5epss 0.01

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing functions in coturn perform unsafe pointer casts from uint8_t * to uint16_t * without alignment checks. When processing a crafted STUN message with odd-aligned…

  • CVE-2026-25613MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.

  • CVE-2025-71002MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    A floating-point exception (FPE) in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.