VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (864)

page 40 of 44
  • CVE-2025-11731LowOct 14, 2025
    risk 0.20cvss 3.1epss 0.00

    A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This…

  • CVE-2021-23472LowNov 3, 2021
    risk 0.20cvss 3.1epss 0.02

    This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.

  • CVE-2025-48756LowMay 24, 2025
    risk 0.19cvss 2.9epss 0.00

    In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small number of bits (e.g., 5 bits) for group number.

  • CVE-2023-49602LowMar 4, 2024
    risk 0.19cvss 2.9epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

  • CVE-2021-23908LowMay 13, 2021
    risk 0.19cvss 2.9epss 0.02

    An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A type confusion issue affects MultiSvSetAttributes in the HiQnet Protocol, leading to remote code execution.

  • CVE-2026-43862LowMay 4, 2026
    risk 0.17cvss 3.7epss 0.00

    In mutt before 2.3.2, the imap_auth_gss security level is mishandled.

  • CVE-2026-5360LowApr 2, 2026
    risk 0.17cvss 3.7epss 0.00

    A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as…

  • CVE-2025-22151LowJan 9, 2025
    risk 0.17cvss 3.7epss 0.00

    Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydantic). The vulnerability…

  • CVE-2021-32696LowJun 18, 2021
    risk 0.17cvss 3.7epss 0.01

    The npm package "striptags" is an implementation of PHP's strip_tags in Typescript. In striptags before version 3.2.0, a type-confusion vulnerability can cause `striptags` to concatenate unsanitized strings when an array-like object is passed in as the `html` parameter. This can…

  • CVE-2024-30266LowApr 4, 2024
    risk 0.14cvss 3.3epss 0.00

    wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this…

  • CVE-2021-41190LowNov 17, 2021
    risk 0.13cvss 3.0epss 0.02

    The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull…

  • CVE-2024-58253LowMay 2, 2025
    risk 0.12cvss 2.9epss 0.00

    In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to invalid UTF-8 conversion that produces an invalid value.

  • CVE-2021-29519LowMay 14, 2021
    risk 0.09cvss 2.5epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. The API of `tf.raw_ops.SparseCross` allows combinations which would result in a `CHECK`-failure and denial of service. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/3d782b7d4…

  • CVE-2021-29513LowMay 14, 2021
    risk 0.09cvss 2.5epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. Calling TF operations with tensors of non-numeric types when the operations expect numeric tensors result in null pointer dereferences. The conversion from Python array to C++…

  • CVE-2022-34918HigJul 4, 2022
    risk 0.03cvss 7.8epss 0.06

    An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but…

  • CVE-2019-15792HigApr 24, 2020
    risk 0.03cvss 7.1epss 0.01

    In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() calls fdget(oldfd), then without further checks passes the resulting file* into shiftfs_real_fdget(), which casts file->private_data, a void*…

  • CVE-2012-0752Feb 16, 2012
    risk 0.01cvss epss 0.09

    Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption)…

  • CVE-2026-64727CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-64704CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

  • CVE-2026-64693MedJul 27, 2026
    risk 0.00cvss 5.5epss 0.00

    A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted image may lead to a denial-of-service.