VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (927)

page 42 of 47
  • CVE-2024-47804MedOct 2, 2024
    risk 0.28cvss 4.3epss 0.01

    If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates…

  • CVE-2023-24599MedMay 29, 2023
    risk 0.28cvss 4.3epss 0.01

    OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion."

  • CVE-2021-23447MedOct 7, 2021
    risk 0.28cvss 5.4epss 0.01

    This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).

  • CVE-2021-23443MedSep 21, 2021
    risk 0.28cvss 5.4epss 0.01

    This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization when the input to be rendered is an array (instead of a string or a SafeValue), even if {{ }} are used.

  • CVE-2019-13118MedJul 1, 2019
    risk 0.28cvss 5.3epss 0.05

    In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

  • CVE-2019-0920MedJun 12, 2019
    risk 0.28cvss 4.3epss 0.06

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who…

  • CVE-2026-15461MedSep 10, 2026
    risk 0.27cvss 5.3epss 0.00

    The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c)…

  • CVE-2026-59152MedJul 6, 2026
    risk 0.26cvss 5.0epss 0.00

    LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server running the LangSmith SDK's TracingMiddleware can cause that server to read an arbitrary file from its local filesystem and…

  • CVE-2026-24914MedFeb 6, 2026
    risk 0.26cvss 4.0epss 0.00

    Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-6939MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by type confusion vulnerability, successful exploitation could cause denial of service.

  • CVE-2023-0083MedMar 10, 2023
    risk 0.26cvss 4.0epss 0.00

    The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to send malicious data, causing the current application to…

  • CVE-2026-44640MedMay 29, 2026
    risk 0.22cvss 4.5epss 0.00

    NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_quic_conn* during dialing, but read as ex_quic_conn* during dialer close. This type confusion causes invalid object interpretation and leads to close-path…

  • CVE-2021-35986LowAug 20, 2021
    risk 0.22cvss 3.3epss 0.03

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Type Confusion vulnerability. An unauthenticated attacker could leverage this vulnerability to read arbitrary system information in the…

  • CVE-2021-28643LowAug 20, 2021
    risk 0.22cvss 3.3epss 0.02

    Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Type Confusion vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the…

  • CVE-2025-43236LowApr 2, 2026
    risk 0.21cvss 3.3epss 0.00

    A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker may be able to cause unexpected app termination.

  • CVE-2026-34595MedMar 31, 2026
    risk 0.21cvss 4.3epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields class-level permission setting on LiveQuery…

  • CVE-2025-27536LowAug 11, 2025
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion.

  • CVE-2025-21082LowJun 8, 2025
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

  • CVE-2025-20063LowJun 8, 2025
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

  • CVE-2024-36278LowJul 2, 2024
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.