Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-704 (不正确的类型转换) — Vulnerability Class 67

67 vulnerabilities classified as CWE-704 (不正确的类型转换). AI Chinese analysis included.

CWE-704 represents a critical software weakness where an application fails to properly convert or cast data between different types, leading to unpredictable behavior or security vulnerabilities. This flaw is typically exploited by attackers who manipulate input data to trigger unintended type conversions, potentially causing buffer overflows, logic errors, or privilege escalation. For instance, forcing a string to be interpreted as an integer might bypass validation checks or corrupt memory structures. To mitigate this risk, developers must implement rigorous input validation and explicitly define type boundaries during conversion processes. Utilizing strongly typed languages and avoiding implicit casts can significantly reduce exposure. Additionally, employing static analysis tools to detect unsafe type operations and conducting thorough code reviews ensures that all conversions are handled safely, preserving data integrity and preventing exploitation of these logical flaws.

MITRE CWE Description
The product does not correctly convert an object, resource, or structure from one type to a different type.
Common Consequences (1)
Other Other
Examples (2)
In this example, depending on the return value of accecssmainframe(), the variable amount can hold a negative value when it is returned. Because the function is declared to return an unsigned value, amount will be implicitly cast to an unsigned number.
unsigned int readdata () { int amount = 0; ... amount = accessmainframe(); ... return amount; }
Bad · C
The following code uses a union to support the representation of different types of messages. It formats messages differently, depending on their type.
#define NAME_TYPE 1 #define ID_TYPE 2 struct MessageBuffer { int msgType; union { char *name; int nameID; }; }; int main (int argc, char **argv) { struct MessageBuffer buf; char *defaultMessage = "Hello World"; buf.msgType = NAME_TYPE; buf.name = defaultMessage; printf("Pointer of buf.name is %p\n", buf.name); /* This particular value for nameID is used to make the code architecture-independent. If coming from untrusted input, it could be any value. */ buf.nameID = (int)(defaultMessage + 1); printf("Pointer of buf.name is now %p\n", buf.name); if (buf.msgType == NAME_TYPE) { printf("Message: %
Bad · C
CVE ID Title CVSS Severity Published
CVE-2018-9942 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17
CVE-2018-9941 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17
CVE-2018-9940 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17
CVE-2018-9939 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17
CVE-2018-9938 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17
CVE-2018-9937 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17
CVE-2018-9936 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17

Vulnerabilities classified as CWE-704 (不正确的类型转换) represent 67 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.