CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
Description
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (864)
page 13 of 44| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-1938 | Hig | 0.57 | 8.8 | 0.01 | Feb 29, 2024 | Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2024-0518 | Hig | 0.57 | 8.8 | 0.01 | Jan 16, 2024 | Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2023-41060 | Hig | 0.57 | 8.8 | 0.01 | Jan 10, 2024 | A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. A remote user may be able to cause kernel code execution. | ||
| CVE-2023-6348 | Hig | 0.57 | 8.8 | 0.01 | Nov 29, 2023 | Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2023-41257 | Hig | 0.57 | 8.8 | 0.02 | Nov 27, 2023 | A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code… | ||
| CVE-2023-5346 | Hig | 0.57 | 8.8 | 0.02 | Oct 5, 2023 | Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2023-4352 | Hig | 0.57 | 8.8 | 0.02 | Aug 15, 2023 | Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2023-32358 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2023 | A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution. | ||
| CVE-2022-4912 | Hig | 0.57 | 8.8 | 0.01 | Jul 29, 2023 | Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2023-32664 | Hig | 0.57 | 8.8 | 0.01 | Jul 19, 2023 | A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. Specially crafted Javascript code inside a malicious PDF document can cause memory corruption and lead to remote code execution. User would need to open a… | ||
| CVE-2023-3216 | Hig | 0.57 | 8.8 | 0.01 | Jun 13, 2023 | Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2023-28162 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2023 | While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9. | ||
| CVE-2023-28243 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | ||
| CVE-2023-24929 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | ||
| CVE-2023-24927 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | ||
| CVE-2023-24885 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | ||
| CVE-2023-1215 | Hig | 0.57 | 8.8 | 0.01 | Mar 7, 2023 | Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2023-1214 | Hig | 0.57 | 8.8 | 0.01 | Mar 7, 2023 | Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2023-22579 | Cri | 0.57 | 9.9 | 0.01 | Feb 16, 2023 | Due to improper parameter filtering in the sequalize js library, can a attacker peform injection. | ||
| CVE-2023-0703 | Hig | 0.57 | 8.8 | 0.01 | Feb 7, 2023 | Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium) |
- risk 0.57cvss 8.8epss 0.01
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.01
Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.01
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. A remote user may be able to cause kernel code execution.
- risk 0.57cvss 8.8epss 0.01
Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.02
A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code…
- risk 0.57cvss 8.8epss 0.02
Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.02
Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.01
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.
- risk 0.57cvss 8.8epss 0.01
Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.01
A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. Specially crafted Javascript code inside a malicious PDF document can cause memory corruption and lead to remote code execution. User would need to open a…
- risk 0.57cvss 8.8epss 0.01
Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.01
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
- risk 0.57cvss 8.8epss 0.02
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 8.8epss 0.01
Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 9.9epss 0.01
Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
- risk 0.57cvss 8.8epss 0.01
Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium)