CWE-704: CWE-704
Yearly Trend
Top Affected Vendors
All CWE-704 CVEs (31)
A type confusion vulnerability in Snapchat's LensCore component could allow attackers to cause denial of service or execute arbitrary code on affected...
May 31, 2024This vulnerability allows attackers to bypass IP address filtering in applications using vulnerable versions of WatsonWebserver or IpMatcher packages....
May 16, 2022This is a critical memory corruption vulnerability in Accusoft ImageGear's TIFF file parser. Attackers can exploit it by providing specially crafted T...
Sep 1, 2020CVE-2023-21651 is a memory corruption vulnerability in Qualcomm's Trusted Execution Environment (TEE) due to incorrect type conversion in secure_io_re...
Aug 8, 2023A type confusion vulnerability in SolarWinds Serv-U allows attackers with administrative privileges to execute arbitrary native code with elevated pri...
Feb 24, 2026A vulnerability in the netmask npm package allows attackers to bypass IP address filtering by submitting specially crafted octal strings. This enables...
Apr 1, 2021This vulnerability allows a remote attacker who has already compromised Chrome's renderer process to exploit heap corruption through a bad cast in the...
Dec 2, 2025A type confusion vulnerability in QuickJS engine's string addition operation allows attackers to trigger callbacks that modify operand types in memory...
Oct 16, 2025This vulnerability involves an invalid downcast from nsTextNode to SVGElement in Mozilla products, which could lead to undefined behavior including po...
Jun 2, 2023This vulnerability involves an incorrect type conversion from 64-bit to 32-bit integers in Mozilla products, allowing memory corruption that could lea...
Dec 8, 2021CVE-2023-6249 is an incorrect type conversion vulnerability in the Zephyr RTOS esp32_ipm_send function, where a signed integer is improperly converted...
Feb 18, 2024A type confusion vulnerability in the Linux kernel's libceph component allows reading/writing to incorrect memory locations when using the msgr2 proto...
Sep 23, 2025This vulnerability allows attackers to execute arbitrary code or cause denial of service by exploiting memory corruption in IOCTL handling. It affects...
Apr 7, 2025A type confusion vulnerability in Tecnomatix Plant Simulation allows attackers to execute arbitrary code by tricking users into opening malicious IGS ...
Oct 10, 2023This CVE is an alignment vulnerability in ImageMagick's property.c file where misaligned memory access for double and float types can cause undefined ...
Jun 16, 2022CVE-2021-1027 is a type confusion vulnerability in Android's SurfaceFlinger component that allows local privilege escalation. Attackers can execute ar...
Dec 15, 2021An unaligned memory access vulnerability in Contiki-NG's RPL implementations can cause system crashes when processing malformed IPv6 packets with odd ...
Nov 27, 2024This vulnerability allows attackers to cause denial of service in OpenPLC Runtime by sending specially crafted EtherNet/IP requests that trigger inval...
Sep 18, 2024This vulnerability allows arbitrary code execution through incorrect type conversion when processing specially crafted DICOM files in OFFIS DCMTK. Att...
Apr 23, 2024This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm devices by sending specially crafted DL NAS TRANSPORT mes...
Apr 1, 2024CVE-2022-25852 is a Denial of Service vulnerability in pg-native and libpq packages where non-array arguments cause casting failures that crash the ap...
Jun 17, 2022This vulnerability in Qualcomm Snapdragon chipsets allows denial of service attacks due to improper hex data decoding in SIB2 OTA messages. When proce...
Jan 13, 2022This vulnerability in the HwNearbyMain module of HarmonyOS allows unauthorized actors to access sensitive information, potentially leading to process ...
Jan 3, 2022This vulnerability in the Net::Netmask Perl module allows attackers to bypass IP-based access controls by using IP addresses with leading zeros. Syste...
Apr 6, 2021A type confusion vulnerability in iccDEV allows malformed ICC color profiles to trigger undefined behavior when loading invalid icImageEncodingType va...
Feb 3, 2026An authenticated MongoDB user can crash the database server by executing a query that targets a collection with an invalid compound wildcard index. Th...
Feb 10, 2026A Linux kernel vulnerability in the perf/dwc_pcie driver causes duplicate pci_dev devices during platform_device_register, leading to memory corruptio...
May 1, 2025A Linux kernel readahead vulnerability causes occasional system hangs when used with NFS (Network File System). The issue occurs when the readahead wi...
Jan 11, 2025This CVE describes a base64 decoding inconsistency in Python's base64 module where '+' and '/' characters are always accepted even when using alternat...
Jan 21, 2026CVE-2026-22041 is a type conversion vulnerability in the Logging Redactor Python library that causes type errors when non-string data is processed wit...
Jan 8, 2026A type compatibility issue in Keylime versions 7.12.0 prevents the registrar from reading agent registration data stored by older versions (like 7.11....
Mar 15, 2025About CWE-704 (CWE-704)
Our database tracks 31 CVEs classified as CWE-704, with 6 rated critical and 19 rated high severity. The average CVSS score for CWE-704 vulnerabilities is 7.7.
External reference: View CWE-704 on MITRE CWE →
Monitor CWE-704 Vulnerabilities
Get alerted when new CWE-704 CVEs affect your infrastructure.
Start Monitoring Free