VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (864)

page 37 of 44
  • CVE-2026-8499MedJun 9, 2026
    risk 0.34cvss 5.3epss 0.00

    The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1.2.9. This is due to the `helpfulcrowd_validate_token()` function using a loose comparison operator (`!=`) instead of a strict…

  • CVE-2022-50590MedNov 6, 2025
    risk 0.34cvss 5.3epss 0.00

    SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including…

  • CVE-2024-13275MedJan 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This issue affects Security Kit: from 0.0.0 before 2.0.3.

  • CVE-2023-44094MedOct 11, 2023
    risk 0.34cvss 5.3epss 0.00

    Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.

  • CVE-2021-39219MedSep 17, 2021
    risk 0.34cvss 6.3epss 0.00

    Wasmtime is an open source runtime for WebAssembly & WASI. Wasmtime before version 0.30.0 is affected by a type confusion vulnerability. As a Rust library the `wasmtime` crate clearly marks which functions are safe and which are `unsafe`, guaranteeing that if consumers never use…

  • CVE-2026-39956MedApr 13, 2026
    risk 0.33cvss 6.1epss 0.00

    jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies…

  • CVE-2026-25204MedApr 13, 2026
    risk 0.33cvss 6.2epss 0.00

    Deserialization of untrusted data vulnerability in Samsung Open Source Escargot Java Script allows denial of service condition via process abort. This issue affects escarogt prior to commit hash 97e8115ab1110bc502b4b5e4a0c689a71520d335

  • CVE-2026-22028MedJan 8, 2026
    risk 0.33cvss 6.1epss 0.00

    Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from being constructed from arbitrary JSON. A regression introduced in Preact 10.26.5 caused this protection to be softened. In applications where values from JSON…

  • CVE-2024-20662MedJan 9, 2024
    risk 0.32cvss 4.9epss 0.02

    Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability

  • CVE-2020-13341MedOct 12, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2. Insufficient permission check allows attacker with developer role to perform various deletions.

  • CVE-2025-43541MedDec 17, 2025
    risk 0.31cvss 4.3epss 0.32

    A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.

  • CVE-2025-32352MedApr 5, 2025
    risk 0.31cvss 4.8epss 0.00

    A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.

  • CVE-2024-37603MedFeb 13, 2025
    risk 0.30cvss 4.6epss 0.00

    An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible type confusion exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the USB interface of the car is needed. With prepared data, an…

  • CVE-2023-51428MedDec 29, 2023
    risk 0.30cvss 4.6epss 0.00

    Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.

  • CVE-2023-51427MedDec 29, 2023
    risk 0.30cvss 4.6epss 0.00

    Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.

  • CVE-2023-51426MedDec 29, 2023
    risk 0.30cvss 4.6epss 0.00

    Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.

  • CVE-2023-23443MedDec 29, 2023
    risk 0.30cvss 4.6epss 0.00

    Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.

  • CVE-2023-23442MedDec 29, 2023
    risk 0.30cvss 4.6epss 0.00

    Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.

  • CVE-2022-3903MedNov 14, 2022
    risk 0.30cvss 4.6epss 0.00

    An incorrect read request flaw was found in the Infrared Transceiver USB driver in the Linux kernel. This issue occurs when a user attaches a malicious USB device. A local user could use this flaw to starve the resources, causing denial of service or potentially crashing the…

  • CVE-2021-23820MedNov 3, 2021
    risk 0.30cvss 5.6epss 0.02

    This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.