VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (864)

page 43 of 44
  • CVE-2021-46878HigApr 11, 2023
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads to type confusion bug that interprets whatever is on the stack as msgpack maps and arrays, leading to use-after-free. This can be used by an attacker to craft a…

  • CVE-2023-1078HigMar 27, 2023
    risk 0.00cvss 7.8epss 0.00

    A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the head of a list causing a type confusion. Local user can trigger this with rds_message_put(). Type confusion leads to `struct…

  • CVE-2023-1077HigMar 27, 2023
    risk 0.00cvss 7.0epss 0.00

    In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,which would then be used as a…

  • CVE-2023-1076MedMar 27, 2023
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in the Linux Kernel. The tun/tap sockets have their socket UID hardcoded to 0 due to a type confusion in their initialization function. While it will be often correct, as tuntap devices require CAP_NET_ADMIN, it may not always be the case, e.g., a non-root user…

  • CVE-2023-1075LowMar 27, 2023
    risk 0.00cvss 3.3epss 0.00

    A flaw was found in the Linux Kernel. The tls_is_tx_ready() incorrectly checks for list emptiness, potentially accessing a type confused entry to the list_head, leaking the last byte of the confused field that overlaps with rec->tx_ready.

  • CVE-2023-23455MedJan 12, 2023
    risk 0.00cvss 5.5epss 0.00

    atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).

  • CVE-2023-23454MedJan 12, 2023
    risk 0.00cvss 5.5epss 0.00

    cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).

  • CVE-2022-3676MedOct 24, 2022
    risk 0.00cvss 6.5epss 0.01

    In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlining to access or modify memory via an incompatible type.

  • CVE-2021-41041MedApr 27, 2022
    risk 0.00cvss 5.3epss 0.01

    In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.

  • CVE-2022-21656HigFeb 22, 2022
    risk 0.00cvss 7.4epss 0.01

    Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the default certificate validation routines has a "type confusion" bug when processing subjectAltNames. This processing allows, for…

  • CVE-2021-46463CriFeb 14, 2022
    risk 0.00cvss 9.8epss 0.02

    njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_then().

  • CVE-2021-24045CriDec 13, 2021
    risk 0.00cvss 9.8epss 0.01

    A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications…

  • CVE-2021-33624MedJun 23, 2021
    risk 0.00cvss 4.7epss 0.01

    In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db.

  • CVE-2020-25575CriSep 14, 2020
    risk 0.00cvss 9.8epss 0.03

    An issue was discovered in the failure crate through 0.1.5 for Rust. It may introduce "compatibility hazards" in some applications, and has a type confusion flaw when downcasting. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.…

  • CVE-2020-10757HigJun 9, 2020
    risk 0.00cvss 7.8epss 0.01

    A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.

  • CVE-2019-19391CriNov 29, 2019
    risk 0.00cvss 9.1epss 0.01

    In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue that leads to arbitrary memory write or read operations, because certain cases involving valid stack levels and > options are mishandled. NOTE: The LuaJIT…

  • CVE-2019-14537CriAug 7, 2019
    risk 0.00cvss 9.8epss 0.06

    YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.

  • CVE-2019-10231CriMar 27, 2019
    risk 0.00cvss 9.8epss 0.03

    Teclib GLPI before 9.4.1.1 is affected by a PHP type juggling vulnerability allowing bypass of authentication. This occurs in Auth::checkPassword() (inc/auth.class.php).

  • CVE-2017-13220HigJan 12, 2018
    risk 0.00cvss 7.8epss 0.00

    An elevation of privilege vulnerability in the Upstream kernel bluez. Product: Android. Versions: Android kernel. Android ID: A-63527053.

  • CVE-2014-1731Apr 26, 2014
    risk 0.00cvss epss 0.03

    core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly check renderer state upon a focus event, which allows remote attackers to cause a denial of…