VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (927)

page 43 of 47
  • CVE-2024-31071LowJul 2, 2024
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

  • CVE-2024-21834LowApr 2, 2024
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

  • CVE-2026-59304LowAug 27, 2026
    risk 0.20cvss 3.1epss 0.00

    Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

  • CVE-2026-8554LowMay 14, 2026
    risk 0.20cvss 3.1epss 0.00

    Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-35541MedApr 3, 2026
    risk 0.20cvss 4.2epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.

  • CVE-2025-11731LowOct 14, 2025
    risk 0.20cvss 3.1epss 0.00

    A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This…

  • CVE-2021-23472LowNov 3, 2021
    risk 0.20cvss 3.1epss 0.02

    This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a string) even if the escape attribute is set.

  • CVE-2025-48756LowMay 24, 2025
    risk 0.19cvss 2.9epss 0.00

    In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small number of bits (e.g., 5 bits) for group number.

  • CVE-2023-49602LowMar 4, 2024
    risk 0.19cvss 2.9epss 0.00

    in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

  • CVE-2021-23908LowMay 13, 2021
    risk 0.19cvss 2.9epss 0.02

    An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A type confusion issue affects MultiSvSetAttributes in the HiQnet Protocol, leading to remote code execution.

  • CVE-2026-43862LowMay 4, 2026
    risk 0.17cvss 3.7epss 0.00

    In mutt before 2.3.2, the imap_auth_gss security level is mishandled.

  • CVE-2026-5360LowApr 2, 2026
    risk 0.17cvss 3.7epss 0.00

    A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as…

  • CVE-2025-22151LowJan 9, 2025
    risk 0.17cvss 3.7epss 0.00

    Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydantic). The vulnerability…

  • CVE-2021-32696LowJun 18, 2021
    risk 0.17cvss 3.7epss 0.01

    The npm package "striptags" is an implementation of PHP's strip_tags in Typescript. In striptags before version 3.2.0, a type-confusion vulnerability can cause `striptags` to concatenate unsanitized strings when an array-like object is passed in as the `html` parameter. This can…

  • CVE-2024-30266LowApr 4, 2024
    risk 0.14cvss 3.3epss 0.00

    wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this…

  • CVE-2021-41190LowNov 17, 2021
    risk 0.13cvss 3.0epss 0.02

    The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull…

  • CVE-2024-58253LowMay 2, 2025
    risk 0.12cvss 2.9epss 0.00

    In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to invalid UTF-8 conversion that produces an invalid value.

  • CVE-2021-29519LowMay 14, 2021
    risk 0.09cvss 2.5epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. The API of `tf.raw_ops.SparseCross` allows combinations which would result in a `CHECK`-failure and denial of service. This is because the implementation(https://github.com/tensorflow/tensorflow/blob/3d782b7d4…

  • CVE-2021-29513LowMay 14, 2021
    risk 0.09cvss 2.5epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. Calling TF operations with tensors of non-numeric types when the operations expect numeric tensors result in null pointer dereferences. The conversion from Python array to C++…

  • CVE-2022-34918HigJul 4, 2022
    risk 0.03cvss 7.8epss 0.06

    An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but…