VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (864)

page 41 of 44
  • CVE-2026-15776HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-58541HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55025HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-55024HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-55022HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-54116MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.

  • CVE-2026-50686HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.

  • CVE-2026-50491HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50421HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50390HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50381MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.

  • CVE-2026-55771HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equals() has inverted null/self branches which could lead to incorrect equality comparisons. The…

  • CVE-2026-58305MedJul 9, 2026
    risk 0.00cvss 6.1epss 0.00

    Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.

  • CVE-2026-57254HigJul 8, 2026
    risk 0.00cvss 7.8epss 0.00

    There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF, it fails to perform proper type checking, ultimately causing the application to crash.

  • CVE-2026-58295HigJul 3, 2026
    risk 0.00cvss 8.3epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-58290HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58289CriJul 3, 2026
    risk 0.00cvss 9.0epss 0.02

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58285HigJul 3, 2026
    risk 0.00cvss 8.3epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58283HigJul 3, 2026
    risk 0.00cvss 8.1epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-57975HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.