VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (864)

page 24 of 44
  • CVE-2025-2016HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt VC6 File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that…

  • CVE-2025-2015HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the…

  • CVE-2025-21356HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2025-21326HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Internet Explorer Remote Code Execution Vulnerability

  • CVE-2024-13169HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.

  • CVE-2024-13049HigDec 30, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt XE File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the…

  • CVE-2024-13047HigDec 30, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the…

  • CVE-2024-12836HigDec 30, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this…

  • CVE-2024-12834HigDec 30, 2024
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this…

  • CVE-2024-11508HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    IrfanView DXF File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2024-11507HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    IrfanView DXF File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2018-9471HigNov 20, 2024
    risk 0.51cvss 7.8epss 0.00

    In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2018-9339HigNov 19, 2024
    risk 0.51cvss 7.8epss 0.00

    In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-45112HigSep 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the context of the current user. This issue occurs when a resource is accessed using a type…

  • CVE-2024-38209HigAug 22, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2024-32919HigJun 13, 2024
    risk 0.51cvss 7.8epss 0.00

    In lwis_add_completion_fence of lwis_fence.c, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-32892HigJun 13, 2024
    risk 0.51cvss 7.8epss 0.00

    In handle_init of goodix/main/main.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-5597HigJun 10, 2024
    risk 0.51cvss 7.8epss 0.01

    Fuji Electric Monitouch V-SFT is vulnerable to a type confusion, which could cause a crash or code execution.

  • CVE-2024-5271HigMay 30, 2024
    risk 0.51cvss 7.8epss 0.00

    Fuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a type confusion, which could result in arbitrary code execution.

  • CVE-2024-32063HigMay 14, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21573)