VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (864)

page 15 of 44
  • CVE-2021-38007HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2018-6122HigNov 2, 2021
    risk 0.57cvss 8.8epss 0.01

    Type confusion in WebAssembly in Google Chrome prior to 66.0.3359.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30818HigOct 28, 2021
    risk 0.57cvss 8.8epss 0.01

    A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, Safari 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-30627HigOct 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30758HigSep 8, 2021
    risk 0.57cvss 8.8epss 0.02

    A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-31008HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.01

    A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 15.1, tvOS 15.1, iOS 15 and iPadOS 15, macOS Monterey 12.0.1, watchOS 8.1. Processing maliciously crafted web content may lead to code execution.

  • CVE-2021-30852HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.01

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-30588HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.02

    Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30517HigJun 4, 2021
    risk 0.57cvss 8.8epss 0.03

    Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30513HigJun 4, 2021
    risk 0.57cvss 8.8epss 0.02

    Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21230HigApr 30, 2021
    risk 0.57cvss 8.8epss 0.02

    Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-23954HigFeb 26, 2021
    risk 0.57cvss 8.8epss 0.01

    Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.

  • CVE-2020-26980HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.03

    A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing JT files. A crafted JT file could trigger a type confusion condition. An…

  • CVE-2020-16015HigJan 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-13547HigDec 22, 2020
    risk 0.57cvss 8.8epss 0.03

    A type confusion vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper use of an object, resulting in memory corruption and arbitrary code execution. An attacker needs…

  • CVE-2020-16103HigDec 14, 2020
    risk 0.57cvss 8.8epss 0.02

    Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior…

  • CVE-2020-9948HigOct 16, 2020
    risk 0.57cvss 8.8epss 0.02

    A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2020-6537HigSep 21, 2020
    risk 0.57cvss 8.8epss 0.02

    Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • CVE-2020-15965HigSep 21, 2020
    risk 0.57cvss 8.8epss 0.03

    Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2020-1911CriSep 4, 2020
    risk 0.57cvss 9.8epss 0.02

    A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes prior to commit fe52854cdf6725c2eaa9e125995da76e6ceb27da allows attackers to potentially execute arbitrary code via crafted JavaScript. Note…