CWE-704: CWE-704

31
Total CVEs
6
Critical
19
High
7.7
Avg CVSS

Yearly Trend

2026
5
2025
7
2024
6
2023
3
2022
5

Top Affected Vendors

1 Qualcomm 4
2 Linux 3
3 Debian 3
4 Google 2
5 Fedoraproject 2
6 Mozilla 2
7 Zephyrproject 1
8 Quickjs Project 1
9 Offis 1
10 Contiki Ng 1

All CWE-704 CVEs (31)

CVE-2024-5436
9.8

A type confusion vulnerability in Snapchat's LensCore component could allow attackers to cause denial of service or execute arbitrary code on affected...

May 31, 2024
CVE-2021-33318
9.8

This vulnerability allows attackers to bypass IP address filtering in applications using vulnerable versions of WatsonWebserver or IpMatcher packages....

May 16, 2022
CVE-2020-6151
9.8

This is a critical memory corruption vulnerability in Accusoft ImageGear's TIFF file parser. Attackers can exploit it by providing specially crafted T...

Sep 1, 2020
CVE-2023-21651
9.3

CVE-2023-21651 is a memory corruption vulnerability in Qualcomm's Trusted Execution Environment (TEE) due to incorrect type conversion in secure_io_re...

Aug 8, 2023
CVE-2025-40540
9.1

A type confusion vulnerability in SolarWinds Serv-U allows attackers with administrative privileges to execute arbitrary native code with elevated pri...

Feb 24, 2026
CVE-2021-28918
9.1

A vulnerability in the netmask npm package allows attackers to bypass IP address filtering by submitting specially crafted octal strings. This enables...

Apr 1, 2021
CVE-2025-13720
8.8

This vulnerability allows a remote attacker who has already compromised Chrome's renderer process to exploit heap corruption through a bad cast in the...

Dec 2, 2025
CVE-2025-62494
8.8

A type confusion vulnerability in QuickJS engine's string addition operation allows attackers to trigger callbacks that modify operand types in memory...

Oct 16, 2025
CVE-2023-25737
8.8

This vulnerability involves an invalid downcast from nsTextNode to SVGElement in Mozilla products, which could lead to undefined behavior including po...

Jun 2, 2023
CVE-2021-43537
8.8

This vulnerability involves an incorrect type conversion from 64-bit to 32-bit integers in Mozilla products, allowing memory corruption that could lea...

Dec 8, 2021
CVE-2023-6249
8.0

CVE-2023-6249 is an incorrect type conversion vulnerability in the Zephyr RTOS esp32_ipm_send function, where a signed integer is improperly converted...

Feb 18, 2024
CVE-2025-39880
7.8

A type confusion vulnerability in the Linux kernel's libceph component allows reading/writing to incorrect memory locations when using the msgr2 proto...

Sep 23, 2025
CVE-2024-43058
7.8

This vulnerability allows attackers to execute arbitrary code or cause denial of service by exploiting memory corruption in IOCTL handling. It affects...

Apr 7, 2025
CVE-2023-45204
7.8

A type confusion vulnerability in Tecnomatix Plant Simulation allows attackers to execute arbitrary code by tricking users into opening malicious IGS ...

Oct 10, 2023
CVE-2022-32547
7.8

This CVE is an alignment vulnerability in ImageMagick's property.c file where misaligned memory access for double and float types can cause undefined ...

Jun 16, 2022
CVE-2021-1027
7.8

CVE-2021-1027 is a type confusion vulnerability in Android's SurfaceFlinger component that allows local privilege escalation. Attackers can execute ar...

Dec 15, 2021
CVE-2024-47181
7.5

An unaligned memory access vulnerability in Contiki-NG's RPL implementations can cause system crashes when processing malformed IPv6 packets with odd ...

Nov 27, 2024
CVE-2024-39589
7.5

This vulnerability allows attackers to cause denial of service in OpenPLC Runtime by sending specially crafted EtherNet/IP requests that trigger inval...

Sep 18, 2024
CVE-2024-28130
7.5

This vulnerability allows arbitrary code execution through incorrect type conversion when processing specially crafted DICOM files in OFFIS DCMTK. Att...

Apr 23, 2024
CVE-2023-33101
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm devices by sending specially crafted DL NAS TRANSPORT mes...

Apr 1, 2024
CVE-2022-25852
7.5

CVE-2022-25852 is a Denial of Service vulnerability in pg-native and libpq packages where non-array arguments cause casting failures that crash the ap...

Jun 17, 2022
CVE-2021-30300
7.5

This vulnerability in Qualcomm Snapdragon chipsets allows denial of service attacks due to improper hex data decoding in SIB2 OTA messages. When proce...

Jan 13, 2022
CVE-2021-39989
7.5

This vulnerability in the HwNearbyMain module of HarmonyOS allows unauthorized actors to access sensitive information, potentially leading to process ...

Jan 3, 2022
CVE-2021-29424
7.5

This vulnerability in the Net::Netmask Perl module allows attackers to bypass IP-based access controls by using IP addresses with leading zeros. Syste...

Apr 6, 2021
CVE-2026-25503
7.1

A type confusion vulnerability in iccDEV allows malformed ICC color profiles to trigger undefined behavior when loading invalid icImageEncodingType va...

Feb 3, 2026
CVE-2026-25613
6.5

An authenticated MongoDB user can crash the database server by executing a query that targets a collection with an invalid compound wildcard index. Th...

Feb 10, 2026
CVE-2025-37746
5.5

A Linux kernel vulnerability in the perf/dwc_pcie driver causes duplicate pci_dev devices during platform_device_register, leading to memory corruptio...

May 1, 2025
CVE-2024-57839
5.5

A Linux kernel readahead vulnerability causes occasional system hangs when used with NFS (Network File System). The issue occurs when the readahead wi...

Jan 11, 2025
CVE-2025-12781
5.3

This CVE describes a base64 decoding inconsistency in Python's base64 module where '+' and '/' characters are always accepted even when using alternat...

Jan 21, 2026
CVE-2026-22041
5.3

CVE-2026-22041 is a type conversion vulnerability in the Logging Redactor Python library that causes type errors when non-string data is processed wit...

Jan 8, 2026
CVE-2025-1057
4.3

A type compatibility issue in Keylime versions 7.12.0 prevents the registrar from reading agent registration data stored by older versions (like 7.11....

Mar 15, 2025

About CWE-704 (CWE-704)

Our database tracks 31 CVEs classified as CWE-704, with 6 rated critical and 19 rated high severity. The average CVSS score for CWE-704 vulnerabilities is 7.7.

External reference: View CWE-704 on MITRE CWE →

Monitor CWE-704 Vulnerabilities

Get alerted when new CWE-704 CVEs affect your infrastructure.

Start Monitoring Free