目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-704 不正确的类型转换 类漏洞列表 66

CWE-704 不正确的类型转换 类弱点 66 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-704指不正确的类型转换或强制转换漏洞,属于逻辑错误类缺陷。当程序未能正确将对象或数据结构从一种类型转换为另一种类型时,可能导致数据损坏或意外行为。攻击者通常利用此漏洞通过构造特定输入,触发错误的类型处理逻辑,从而引发崩溃、数据泄露或执行恶意代码。开发者应避免使用不安全的强制转换,确保类型转换前后数据完整性,并实施严格的输入验证与类型检查机制,以消除潜在风险。

MITRE CWE 官方描述
CWE:CWE-704 Incorrect Type Conversion or Cast(不正确的类型转换或强制类型转换) 英文:The product does not correctly convert an object, resource, or structure from one type to a different type. 译文:该产品未能正确地将对象、资源或结构从一种类型转换为另一种类型。
常见影响 (1)
Other Other
代码示例 (2)
In this example, depending on the return value of accecssmainframe(), the variable amount can hold a negative value when it is returned. Because the function is declared to return an unsigned value, amount will be implicitly cast to an unsigned number.
unsigned int readdata () { int amount = 0; ... amount = accessmainframe(); ... return amount; }
Bad · C
The following code uses a union to support the representation of different types of messages. It formats messages differently, depending on their type.
#define NAME_TYPE 1 #define ID_TYPE 2 struct MessageBuffer { int msgType; union { char *name; int nameID; }; }; int main (int argc, char **argv) { struct MessageBuffer buf; char *defaultMessage = "Hello World"; buf.msgType = NAME_TYPE; buf.name = defaultMessage; printf("Pointer of buf.name is %p\n", buf.name); /* This particular value for nameID is used to make the code architecture-independent. If coming from untrusted input, it could be any value. */ buf.nameID = (int)(defaultMessage + 1); printf("Pointer of buf.name is now %p\n", buf.name); if (buf.msgType == NAME_TYPE) { printf("Message: %
Bad · C
CVE ID 标题 CVSS 风险等级 Published
CVE-2018-9941 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17
CVE-2018-9940 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17
CVE-2018-9939 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17
CVE-2018-9938 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17
CVE-2018-9937 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17
CVE-2018-9936 Foxit Reader 安全漏洞 — Foxit Reader 8.8 - 2018-05-17

CWE-704(不正确的类型转换) 是常见的弱点类别,本平台收录该类弱点关联的 66 条 CVE 漏洞。