VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (864)

page 32 of 44
  • CVE-2024-20012MedFeb 5, 2024
    risk 0.44cvss 6.7epss 0.00

    In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358566; Issue ID: ALPS08358566.

  • CVE-2024-20010MedFeb 5, 2024
    risk 0.44cvss 6.7epss 0.00

    In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358560; Issue ID: ALPS08358560.

  • CVE-2023-48694MedDec 5, 2023
    risk 0.44cvss 6.8epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference and type confusion vulnerabilities in Azure RTOS USBX. The affected…

  • CVE-2023-32835MedNov 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In keyinstall, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08157918; Issue ID: ALPS08157918.

  • CVE-2023-32834MedNov 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In secmem, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08161762; Issue ID: ALPS08161762.

  • CVE-2023-32818MedNov 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896 & ALPS08013430; Issue ID: ALPS07867715.

  • CVE-2023-28575MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.

  • CVE-2023-2234MedJul 10, 2023
    risk 0.44cvss 6.8epss 0.01

    Union variant confusion allows any malicious BT controller to execute arbitrary code on the Zephyr host.

  • CVE-2023-20768MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07559800.

  • CVE-2023-20673MedMay 15, 2023
    risk 0.44cvss 6.7epss 0.00

    In vcu, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519103; Issue ID: ALPS07519103.

  • CVE-2023-21056MedMar 24, 2023
    risk 0.44cvss 6.7epss 0.00

    In lwis_slc_buffer_free of lwis_device_slc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2023-20616MedFeb 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07560720.

  • CVE-2022-25721MedJan 9, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in video driver due to type confusion error during video playback

  • CVE-2022-26435MedAug 1, 2022
    risk 0.44cvss 6.7epss 0.00

    In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138435; Issue ID: ALPS07138435.

  • CVE-2022-26433MedAug 1, 2022
    risk 0.44cvss 6.7epss 0.00

    In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138400; Issue ID: ALPS07138400.

  • CVE-2022-26430MedAug 1, 2022
    risk 0.44cvss 6.7epss 0.00

    In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032521; Issue ID: ALPS07032521.

  • CVE-2020-0336MedSep 17, 2020
    risk 0.44cvss 6.7epss 0.00

    In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153467444

  • CVE-2026-40683HigApr 14, 2026
    risk 0.43cvss 7.7epss 0.00

    In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean…

  • CVE-2023-46842MedMay 16, 2024
    risk 0.43cvss 6.5epss 0.09

    Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to pass 32-bit-mode hypercall arguments to values outside of the range 32-bit code would be able to set them to. When processing of…

  • CVE-2019-0810HigApr 9, 2019
    risk 0.43cvss 7.5epss 0.12

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0812, CVE-2019-0829,…