VYPR

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

BaseIncomplete

Description

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (864)

page 7 of 44
  • CVE-2026-24874CriJan 27, 2026
    risk 0.59cvss 9.1epss 0.00

    Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.

  • CVE-2024-25575HigApr 30, 2024
    risk 0.59cvss 8.8epss 0.18

    A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code…

  • CVE-2023-36017HigNov 14, 2023
    risk 0.59cvss 8.8epss 0.25

    Windows Scripting Engine Memory Corruption Vulnerability

  • CVE-2023-4069HigAug 3, 2023
    risk 0.59cvss 8.8epss 0.25

    Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-2936HigMay 30, 2023
    risk 0.59cvss 8.8epss 0.23

    Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-2935HigMay 30, 2023
    risk 0.59cvss 8.8epss 0.24

    Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-1232HigJul 25, 2022
    risk 0.59cvss 8.8epss 0.17

    Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-46743CriMar 29, 2022
    risk 0.59cvss 9.1epss 0.01

    In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. NOTE: this provides a…

  • CVE-2021-38001HigNov 23, 2021
    risk 0.59cvss 8.8epss 0.27

    Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-22354CriJun 30, 2021
    risk 0.59cvss 9.1epss 0.01

    There is an Information Disclosure Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause out-of-bounds read.

  • CVE-2020-25016CriAug 29, 2020
    risk 0.59cvss 9.1epss 0.02

    A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leading to (for example) dereferencing of arbitrary pointers or disclosure of uninitialized memory. This occurs because structs can be treated as bytes for read and write operations.

  • CVE-2020-5754CriJun 15, 2020
    risk 0.59cvss 9.1epss 0.02

    Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in crashing or reading memory contents of the Webroot endpoint agent.

  • CVE-2019-5183CriJan 25, 2020
    risk 0.59cvss 9.0epss 0.02

    An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031.18002. A specially crafted pixel shader can cause a type confusion issue, leading to potential code execution. An attacker can provide a…

  • CVE-2019-6214HigMar 5, 2019
    risk 0.59cvss 8.6epss 0.04

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to break out of its sandbox.

  • CVE-2025-12428HigNov 10, 2025
    risk 0.58cvss 8.8epss 0.07

    Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-53145HigAug 12, 2025
    risk 0.58cvss 8.8epss 0.06

    Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

  • CVE-2025-53144HigAug 12, 2025
    risk 0.58cvss 8.8epss 0.06

    Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

  • CVE-2025-5959HigJun 11, 2025
    risk 0.58cvss 8.8epss 0.12

    Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-2135HigMar 10, 2025
    risk 0.58cvss 8.8epss 0.07

    Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-0291HigJan 8, 2025
    risk 0.58cvss 8.8epss 0.07

    Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)