Skip to main content

Threats Tagged 'cwe-704'

View all threats tagged with 'cwe-704'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-704

Threats Tagged 'cwe-704'

Click on any threat for detailed analysis and mitigation recommendations

vLLM versions prior to 0.30.0 contain an improper input validation vulnerability in the /inference/v1/generate endpoint. This flaw allows crafted inputs in several fields to cause termination of the shared EngineCore, cross-request cache poisoning or retrieval, and altered transport semantics. The issue is resolved in version 0.30.0.

Join the discussion

Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Join the discussion

An out-of-bounds read vulnerability exists in iccDEV versions prior to 2.3.2.1 due to a size_t underflow in the CIccEmbedIO::Read8() function. This occurs when parsing ICC profiles containing specific embedded profile tags. The issue is patched in version 2.3.2.1. No known workarounds are available.

Join the discussion

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check — when a registration is submitted with a 61–70 character username, WordPress core rejects it with a WP_Error object, but absint() coerces that object to the integer 1 before the error check can short-circuit execution, causing the plugin to bind and return a transient-backed autologin nonce tied to user ID 1. This makes it possible for unauthenticated attackers to log in as the site's Administrator account (user ID 1), resulting in full administrative takeover of the site.

Join the discussion

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check — when a registration is submitted with a 61–70 character username, WordPress core rejects it with a WP_Error object, but absint() coerces that object to the integer 1 before the error check can short-circuit execution, causing the plugin to bind and return a transient-backed autologin nonce tied to user ID 1. This makes it possible for unauthenticated attackers to log in as the site's Administrator account (user ID 1), resulting in full administrative takeover of the site.

Join the discussion

CVE-2026-53798 is a privilege confusion vulnerability in rsync versions up to 3.4.4. It arises from incorrect handling of uid/gid lookups in the name-converter subprocess, where empty responses are misinterpreted as root (uid/gid 0). This flaw allows local attackers to cause transferred files to be owned by root by manipulating name-converter responses. The vulnerability is classified under CWE-704 (Incorrect Type Conversion or Cast) and has a medium severity with a CVSS score of 6.9.

Join the discussion

Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ephemeral value that is not 32 bytes long. The client-side Curve25519Kex::compute_shared_secret function in russh/src/kex/curve25519.rs passes the decoded exchange.server_ephemeral value to clone_from_slice without validating its length, causing a deterministic panic before the server host key is verified. The panic terminates the spawned client session task and surfaces as a JoinError, while the embedding process normally remains running. This issue is fixed in version 0.62.4.

Join the discussion

The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs. The panic terminates the entire kuma-cp process, HTTP API, the health and readiness endpoints, and xDS. Unauthenticated access to the dataplane gRPC server can trigger the crash with a malformed token A single request is a transient interruption; sustaining an outage requires repeated requests.

Join the discussion

Two vulnerabilities have been identified in the TPM 2.0 reference implementation: an information leakage vulnerability (CVE-2026-6726) allowing privileged local attackers to obtain credentials for falsified TPM keys, and a timing side-channel vulnerability (CVE-2026-6727) in RSA OAEP decryption that could enable decryption of ciphertexts encrypted to TPM-managed RSA keys. Exploitation requires privileged local access to the TPM command interface. Successful attacks could lead to forged TPM attestations and decryption of sensitive data. Multiple vendors have released firmware and software updates incorporating fixes. Users should apply these updates as provided by their platform or TPM vendor. Cloud providers using software TPMs may have also deployed patches and customers should consult their providers. The overall impact depends on the TPM implementation and usage context.

Join the discussion

Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.

Join the discussion

Showing 1 to 10 of 32 results

Filters:Tag: cwe-704
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses