Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-681 (数值类型间的不正确转换) — Vulnerability Class 57

57 vulnerabilities classified as CWE-681 (数值类型间的不正确转换). AI Chinese analysis included.

CWE-681 represents a logic weakness arising from improper type conversion, where data is truncated or misinterpreted during transitions between numeric types, such as casting a long integer to a smaller integer. This flaw typically enables attackers to exploit unexpected value changes, leading to critical security failures like buffer overflows, integer overflows, or logic bypasses in authentication and financial calculations. By manipulating input values that exceed the target type’s capacity, adversaries can trigger dangerous behaviors that compromise system integrity or confidentiality. Developers mitigate this risk by implementing rigorous input validation, ensuring explicit checks for range boundaries before conversion, and utilizing safe libraries that handle type casting securely. Additionally, employing static analysis tools and adhering to strict coding standards helps identify potential conversion errors early in the development lifecycle, preventing these vulnerabilities from reaching production environments.

MITRE CWE Description
When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.
Common Consequences (1)
Other, Integrity Unexpected State, Quality Degradation
The program could wind up using the wrong number and generate incorrect results. If the number is used to allocate resources or make a security decision, then this could introduce a vulnerability.
Mitigations (1)
Implementation Avoid making conversion between numeric types. Always check for the allowed ranges.
Examples (2)
In the following Java example, a float literal is cast to an integer, thus causing a loss of precision.
int i = (int) 33457.8f;
Bad · Java
This code adds a float and an integer together, casting the result to an integer.
$floatVal = 1.8345; $intVal = 3; $result = (int)$floatVal + $intVal;
Bad · PHP
CVE ID Title CVSS Severity Published
CVE-2026-47539 NVIDIA vGPU Linux内核层数值转换漏洞 — Virtual GPU Manager 6.7 Medium 2026-09-30
CVE-2026-47508 NVIDIA驱动内核层数值转换错误致代码执行漏洞 — GeForce 7.8 High 2026-09-30
CVE-2026-77412 RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client — amqp091-go 8.9 High 2026-09-16
CVE-2026-69438 Microsoft JScript Remote Code Execution Vulnerability — Windows 10 Version 1607 8.1 High 2026-09-08
CVE-2026-84963 Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser — C Driver 5.3 Medium 2026-09-03
CVE-2026-84966 BSON element injection via NUL-embedded document keys in builder append — C++ Driver 5.1 Medium 2026-09-03
CVE-2026-84970 Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser — C++ Driver 6.2 Medium 2026-09-03
CVE-2026-82522 libjxl < 0.12.0 Container Box Parser Integer Underflow via 32-bit Size Truncation — libjxl 5.4 Medium 2026-09-02
CVE-2026-82457 su-exec through 0.3 Privilege Escalation via Numeric User ID — su-exec 7.8 High 2026-08-29
CVE-2026-75145 FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer — FFmpeg 5.8 Medium 2026-08-19
CVE-2026-19879 Io.undertow/undertow: undertow: http response header integrity issue due to character truncation — Red Hat build of Apache Camel for Spring Boot 4 5.3 Medium 2026-08-14
CVE-2026-6426 Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access — Red Hat Enterprise Linux 10 4.4 Medium 2026-08-10
CVE-2026-50402 NTFS Elevation of Privilege Vulnerability — Windows 10 Version 1607 7.8 High 2026-07-14
CVE-2026-53923 vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflow — vllm - - 2026-06-22
CVE-2026-9143 Incorrect Conversion between Numeric Types in NI grpc-device due to missing range checks in CodeGen — grpc-device 3.7 Low 2026-06-19
CVE-2026-24192 NVIDIA Display Driver 安全漏洞 — GeForce 7.8 High 2026-05-26
CVE-2026-26178 Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability — Windows 10 Version 1607 8.8 High 2026-04-14
CVE-2026-34945 Wasmtime leaks host data with 64-bit tables and Winch — wasmtime 6.5AI Medium AI 2026-04-09
CVE-2026-24174 NVIDIA Triton Inference Server 安全漏洞 — Triton Inference Server 7.5 High 2026-04-07
CVE-2026-34610 leancrypto: Integer truncation in X.509 name parser enables certificate identity impersonation — leancrypto 5.9 Medium 2026-04-02
CVE-2026-34550 iccDEV: UB at IccIO.cpp — iccDEV 6.2 Medium 2026-03-31
CVE-2026-34548 iccDEV: UB at IccUtilXml.cpp — iccDEV 6.2 Medium 2026-03-31
CVE-2026-4602 jsrsasign 安全漏洞 — jsrsasign 7.5 High 2026-03-23
CVE-2025-10543 Eclipse Paho Go MQTT v3.1 library 安全漏洞 — paho.mqtt.golang (Go MQTT v3.1 library) 7.5AI High AI 2025-12-02
CVE-2025-58063 CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion — coredns 7.1 High 2025-09-09
CVE-2025-53733 Microsoft Word Remote Code Execution Vulnerability — Microsoft 365 Apps for Enterprise 8.4 High 2025-08-12
CVE-2025-24059 Windows Common Log File System Driver Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High 2025-03-11
CVE-2024-49093 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability — Windows 11 Version 24H2 8.8 High 2024-12-10
CVE-2024-7747 Wallet for WooCommerce <= 1.5.6 - Authenticated (Subscriber+) Incorrect Conversion between Numeric Types — Wallet for WooCommerce 6.5 Medium 2024-11-28
CVE-2022-40225 Siemens SIPLUS TIM 1531 IRC 安全漏洞 — SIPLUS TIM 1531 IRC 6.5 Medium 2024-06-11

Vulnerabilities classified as CWE-681 (数值类型间的不正确转换) represent 57 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.