VYPR

CWE-704

Incorrect Type Conversion or Cast

ClassIncomplete

Description

The product does not correctly convert an object, resource, or structure from one type to a different type.

Hierarchy (View 1000)

CVEs mapped to this weakness (295)

page 8 of 15
  • CVE-2022-22102HigSep 2, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in multimedia due to incorrect type conversion while adding data in Snapdragon Auto

  • CVE-2021-35091HigJun 14, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible out of bounds read due to improper typecasting while handling page fault for global memory in Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2021-35105HigApr 1, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2018-12386HigOct 18, 2018
    risk 0.54cvss 8.1epss 0.13

    A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox <…

  • CVE-2018-12453HigJun 16, 2018
    risk 0.54cvss 7.5epss 0.24

    Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream.

  • CVE-2017-5717HigDec 12, 2017
    risk 0.54cvss 7.8epss 0.01

    Type Confusion in Content Protection HECI Service in Intel Graphics Driver allows unprivileged user to elevate privileges via local access.

  • CVE-2016-7617HigFeb 20, 2017
    risk 0.54cvss 7.8epss 0.05

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (type confusion) via a crafted app.

  • CVE-2021-35110HigApr 1, 2022
    risk 0.53cvss 8.1epss 0.00

    Possible buffer overflow to improper validation of hash segment of file while allocating memory in Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2017-7813HigJun 11, 2018
    risk 0.53cvss 8.2epss 0.02

    Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier…

  • CVE-2026-27809CriFeb 26, 2026
    risk 0.52cvss 9.1epss 0.01

    psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past the expected row size), decode_rle() raises ValueError which propagated all the…

  • CVE-2023-6249HigFeb 18, 2024
    risk 0.52cvss 8.0epss 0.00

    Signed to unsigned conversion esp32_ipm_send

  • CVE-2026-69585HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

  • CVE-2026-6726HigAug 11, 2026
    risk 0.51cvss 7.9epss 0.00

    An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and…

  • CVE-2024-43058HigApr 7, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing IOCTL calls.

  • CVE-2018-9339HigNov 19, 2024
    risk 0.51cvss 7.8epss 0.00

    In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-35303HigJun 11, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0012), Tecnomatix Plant Simulation V2404 (All versions < V2404.0001). The affected applications contain a type confusion vulnerability while parsing specially crafted MODEL files. This…

  • CVE-2023-45204HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain a type confusion vulnerability while parsing specially crafted IGS files. This…

  • CVE-2021-3578HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly…

  • CVE-2021-1027HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged process due to improper casting. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-1923HigSep 8, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect pointer argument passed to trusted application TA could result in un-intended memory operations in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT