VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (927)

page 34 of 47
  • CVE-2025-53810MedSep 9, 2025
    risk 0.44cvss 6.7epss 0.00

    Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53808MedSep 9, 2025
    risk 0.44cvss 6.7epss 0.00

    Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-22153HigJan 23, 2025
    risk 0.44cvss 7.9epss 0.00

    RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Via a type confusion bug in versions of the CPython interpreter starting in 3.11 and prior to 3.13.2 when using `try/except*`,…

  • CVE-2024-20106MedNov 4, 2024
    risk 0.44cvss 6.7epss 0.00

    In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08960505; Issue ID: MSV-1590.

  • CVE-2024-20012MedFeb 5, 2024
    risk 0.44cvss 6.7epss 0.00

    In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358566; Issue ID: ALPS08358566.

  • CVE-2024-20010MedFeb 5, 2024
    risk 0.44cvss 6.7epss 0.00

    In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358560; Issue ID: ALPS08358560.

  • CVE-2023-48694MedDec 5, 2023
    risk 0.44cvss 6.8epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference and type confusion vulnerabilities in Azure RTOS USBX. The affected…

  • CVE-2023-32835MedNov 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In keyinstall, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08157918; Issue ID: ALPS08157918.

  • CVE-2023-32834MedNov 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In secmem, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08161762; Issue ID: ALPS08161762.

  • CVE-2023-32818MedNov 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896 & ALPS08013430; Issue ID: ALPS07867715.

  • CVE-2023-28575MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.

  • CVE-2023-2234MedJul 10, 2023
    risk 0.44cvss 6.8epss 0.01

    Union variant confusion allows any malicious BT controller to execute arbitrary code on the Zephyr host.

  • CVE-2023-20768MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07559800.

  • CVE-2023-20673MedMay 15, 2023
    risk 0.44cvss 6.7epss 0.00

    In vcu, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519103; Issue ID: ALPS07519103.

  • CVE-2023-21056MedMar 24, 2023
    risk 0.44cvss 6.7epss 0.00

    In lwis_slc_buffer_free of lwis_device_slc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2023-20616MedFeb 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07560720.

  • CVE-2022-25721MedJan 9, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in video driver due to type confusion error during video playback

  • CVE-2022-26435MedAug 1, 2022
    risk 0.44cvss 6.7epss 0.00

    In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138435; Issue ID: ALPS07138435.

  • CVE-2022-26433MedAug 1, 2022
    risk 0.44cvss 6.7epss 0.00

    In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07138400; Issue ID: ALPS07138400.

  • CVE-2022-26430MedAug 1, 2022
    risk 0.44cvss 6.7epss 0.00

    In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032521; Issue ID: ALPS07032521.