VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (927)

page 22 of 47
  • CVE-2026-79175HigAug 25, 2026
    risk 0.54cvss 8.3epss 0.00

    Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-13803HigJun 30, 2026
    risk 0.54cvss 8.3epss 0.00

    Type Confusion in Chrome Tabs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-7914HigMay 6, 2026
    risk 0.54cvss 8.3epss 0.00

    Type Confusion in Accessibility in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-6119HigSep 3, 2024
    risk 0.54cvss 7.5epss 0.67

    Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can…

  • CVE-2023-4068HigAug 3, 2023
    risk 0.54cvss 8.1epss 0.16

    Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-45635HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.01

    Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

  • CVE-2024-53427HigFeb 26, 2025
    risk 0.53cvss 8.1epss 0.00

    decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-based buffer overflow and out-of-bounds write, as demonstrated by use of --slurp with subtraction, such as a filter of .-. when the input…

  • CVE-2024-49119HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-5158HigMay 22, 2024
    risk 0.53cvss 8.1epss 0.01

    Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-34394HigMay 2, 2024
    risk 0.53cvss 8.1epss 0.01

    libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes XmlNode::get_local_namespaces()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of…

  • CVE-2024-34393HigMay 2, 2024
    risk 0.53cvss 8.1epss 0.01

    libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems),…

  • CVE-2024-34392HigMay 2, 2024
    risk 0.53cvss 8.1epss 0.01

    libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes _wrap__xmlNode_nsDef_get()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service…

  • CVE-2024-34391HigMay 2, 2024
    risk 0.53cvss 8.1epss 0.01

    libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems), data…

  • CVE-2023-4070HigAug 3, 2023
    risk 0.53cvss 8.1epss 0.01

    Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-35297HigJul 11, 2023
    risk 0.53cvss 8.1epss 0.01

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

  • CVE-2023-0286HigFeb 8, 2023
    risk 0.53cvss 7.4epss 0.59

    There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This…

  • CVE-2020-36460HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the model crate through 2020-11-10 for Rust. The Shared data structure has an implementation of the Send and Sync traits without regard for the inner type.

  • CVE-2019-11706HigJul 23, 2019
    risk 0.53cvss 7.5epss 0.10

    A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulting in a crash. This vulnerability affects Thunderbird < 60.7.1.

  • CVE-2026-45764CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in Suricata. Crafted traffic may cause…

  • CVE-2026-69717HigSep 8, 2026
    risk 0.52cvss 8.0epss 0.01

    Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.