VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (864)

page 13 of 44
  • CVE-2024-1938HigFeb 29, 2024
    risk 0.57cvss 8.8epss 0.01

    Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-0518HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-41060HigJan 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. A remote user may be able to cause kernel code execution.

  • CVE-2023-6348HigNov 29, 2023
    risk 0.57cvss 8.8epss 0.01

    Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-41257HigNov 27, 2023
    risk 0.57cvss 8.8epss 0.02

    A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code…

  • CVE-2023-5346HigOct 5, 2023
    risk 0.57cvss 8.8epss 0.02

    Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4352HigAug 15, 2023
    risk 0.57cvss 8.8epss 0.02

    Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-32358HigAug 14, 2023
    risk 0.57cvss 8.8epss 0.01

    A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.

  • CVE-2022-4912HigJul 29, 2023
    risk 0.57cvss 8.8epss 0.01

    Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-32664HigJul 19, 2023
    risk 0.57cvss 8.8epss 0.01

    A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. Specially crafted Javascript code inside a malicious PDF document can cause memory corruption and lead to remote code execution. User would need to open a…

  • CVE-2023-3216HigJun 13, 2023
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-28162HigJun 2, 2023
    risk 0.57cvss 8.8epss 0.01

    While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.

  • CVE-2023-28243HigApr 11, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

  • CVE-2023-24929HigApr 11, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

  • CVE-2023-24927HigApr 11, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

  • CVE-2023-24885HigApr 11, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

  • CVE-2023-1215HigMar 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-1214HigMar 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-22579CriFeb 16, 2023
    risk 0.57cvss 9.9epss 0.01

    Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.

  • CVE-2023-0703HigFeb 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium)