VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (864)

page 34 of 44
  • CVE-2024-5843MedJun 11, 2024
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate security UI via a malicious file. (Chromium security severity: Medium)

  • CVE-2023-50433MedApr 29, 2024
    risk 0.42cvss 6.5epss 0.00

    marshall in dhcp_packet.c in simple-dhcp-server through ec976d2 allows remote attackers to cause a denial of service by sending a malicious DHCP packet. The crash is caused by a type confusion bug that results in a large memory allocation; when this memory allocation fails the…

  • CVE-2023-24944MedMay 9, 2023
    risk 0.42cvss 6.5epss 0.01

    Windows Bluetooth Driver Information Disclosure Vulnerability

  • CVE-2022-1869MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    Type Confusion in V8 in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-1176HigMar 31, 2022
    risk 0.42cvss 7.5epss 0.01

    Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.

  • CVE-2020-36229HigJan 26, 2021
    risk 0.42cvss 7.5epss 0.04

    A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.

  • CVE-2019-8597MedDec 18, 2019
    risk 0.42cvss 6.5epss 0.02

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary…

  • CVE-2019-11750MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

  • CVE-2019-9816MedJul 23, 2019
    risk 0.42cvss 5.9epss 0.06

    A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled…

  • CVE-2019-6984MedJan 28, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter a Use-After-Free or Type Confusion and crash during handling of certain PDF files that embed specifically crafted 3D content, due to the use of a…

  • CVE-2017-5094MedOct 27, 2017
    risk 0.42cvss 6.5epss 0.02

    Type confusion in extensions JavaScript bindings in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted HTML page.

  • CVE-2025-25277MedMar 16, 2026
    risk 0.41cvss 6.3epss 0.00

    in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios.

  • CVE-2024-38207MedAug 23, 2024
    risk 0.41cvss 6.3epss 0.00

    Microsoft Edge (HTML-based) Memory Corruption Vulnerability

  • CVE-2023-1235MedMar 7, 2023
    risk 0.41cvss 6.3epss 0.00

    Type confusion in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted UI interaction. (Chromium security severity: Low)

  • CVE-2022-4205MedJan 27, 2023
    risk 0.41cvss 6.3epss 0.01

    In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.

  • CVE-2021-23440HigSep 12, 2021
    risk 0.41cvss 7.3epss 0.02

    This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.

  • CVE-2019-2692MedApr 23, 2019
    risk 0.41cvss 6.3epss 0.01

    Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Connectors…

  • CVE-2026-9334HigJun 3, 2026
    risk 0.40cvss 7.3epss 0.00

    Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference under dupkeys_as_arrayref. The branch reached for a duplicate key tests `SvTYPE…

  • CVE-2026-28822MedMar 25, 2026
    risk 0.40cvss 6.2epss 0.00

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An attacker may be able to cause unexpected app termination.

  • CVE-2025-43297MedSep 15, 2025
    risk 0.40cvss 6.2epss 0.00

    A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26. An app may be able to cause a denial-of-service.