VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (864)

page 39 of 44
  • CVE-2019-13118MedJul 1, 2019
    risk 0.28cvss 5.3epss 0.05

    In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

  • CVE-2019-0920MedJun 12, 2019
    risk 0.28cvss 4.3epss 0.06

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who…

  • CVE-2026-53600medJul 8, 2026
    risk 0.26cvss epss

    ## Summary `async-tar` v0.6.0 mis-applies a buffered PAX `size` extension to an intermediary extension header (a GNU longname `L`, a GNU longlink `K`, or a PAX `x`/`g` header) instead of to the next *file* entry. POSIX requires a PAX extended-header record set to describe the…

  • CVE-2026-59152MedJul 6, 2026
    risk 0.26cvss 5.0epss 0.00

    LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server running the LangSmith SDK's TracingMiddleware can cause that server to read an arbitrary file from its local filesystem and…

  • CVE-2026-24914MedFeb 6, 2026
    risk 0.26cvss 4.0epss 0.00

    Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-6939MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by type confusion vulnerability, successful exploitation could cause denial of service.

  • CVE-2023-0083MedMar 10, 2023
    risk 0.26cvss 4.0epss 0.00

    The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to send malicious data, causing the current application to…

  • CVE-2026-44640MedMay 29, 2026
    risk 0.22cvss 4.5epss 0.00

    NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_quic_conn* during dialing, but read as ex_quic_conn* during dialer close. This type confusion causes invalid object interpretation and leads to close-path…

  • CVE-2021-35986LowAug 20, 2021
    risk 0.22cvss 3.3epss 0.03

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Type Confusion vulnerability. An unauthenticated attacker could leverage this vulnerability to read arbitrary system information in the…

  • CVE-2021-28643LowAug 20, 2021
    risk 0.22cvss 3.3epss 0.02

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Type Confusion vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the…

  • CVE-2025-43236LowApr 2, 2026
    risk 0.21cvss 3.3epss 0.00

    A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker may be able to cause unexpected app termination.

  • CVE-2026-34595MedMar 31, 2026
    risk 0.21cvss 4.3epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields class-level permission setting on LiveQuery…

  • CVE-2025-27536LowAug 11, 2025
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion.

  • CVE-2025-21082LowJun 8, 2025
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

  • CVE-2025-20063LowJun 8, 2025
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

  • CVE-2024-36278LowJul 2, 2024
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

  • CVE-2024-31071LowJul 2, 2024
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

  • CVE-2024-21834LowApr 2, 2024
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

  • CVE-2026-8554LowMay 14, 2026
    risk 0.20cvss 3.1epss 0.00

    Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-35541MedApr 3, 2026
    risk 0.20cvss 4.2epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.