CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

745 vulnerabilities with CWE-843
CVE-2026-7337 HIGH
Google Chrome <147.0.7727.138 - Type Confusion RCE
CVSS 8.8
CVE-2026-6732 MEDIUM
Libxml2: libxml2: denial of service via crafted xsd-validated document
CVSS 6.5
CVE-2026-31502 HIGH
team: fix header_ops type confusion with non-Ethernet ports
CVSS 7.8
CVE-2026-6363 HIGH
Google Chrome < 147.0.7727.101 - Out-of-Bounds Access
CVSS 8.8
CVE-2026-6307 HIGH
Google Chrome <147.0.7727.101 - Type Confusion
CVSS 8.8
CVE-2026-6301 HIGH
Google Chrome <147.0.7727.101 - Type Confusion
CVSS 8.8
CVE-2026-27298 HIGH
Adobe Framemaker | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)
CVSS 7.8
CVE-2026-40683 HIGH
OpenStack Keystone <25.0.1 - Auth Bypass
CVSS 7.7
CVE-2026-26162 HIGH
Windows OLE Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-20806 MEDIUM
Windows COM Server Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-39956 MEDIUM
jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure
CVSS 6.1
CVE-2026-40446 MEDIUM
Samsung Open Source Escargot 97e8115ab1110bc502b4b5e4a0c689a71520d335 - Type Confusion
CVSS 6.9
CVE-2026-25204 MEDIUM
Samsung Open Source Escargot - Denial of Service
CVSS 6.2
CVE-2026-5496 HIGH
Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-5914 HIGH
Google Chrome <147.0.7727.55 - Memory Corruption
CVSS 8.8
CVE-2026-5871 HIGH
Google Chrome <147.0.7727.55 - Type Confusion
CVSS 8.8
CVE-2026-5865 HIGH
Google Chrome <147.0.7727.55 - Type Confusion
CVSS 8.8
CVE-2026-27144 HIGH
Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
CVSS 7.1
CVE-2026-34379 HIGH
OpenEXR has a misaligned write in LossyDctDecoder_execute leading to undefined behavior (DWA/DWAB decompression)
CVSS 7.1
CVE-2026-35541 MEDIUM
Roundcube Webmail <1.5.14 - Auth Bypass
CVSS 4.2
CVE-2026-5360 LOW
Free5GC aper type confusion
CVSS 3.7
CVE-2026-34595 MEDIUM
Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value
CVSS 4.3
CVE-2026-33940 HIGH
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
CVSS 8.1
CVE-2026-33938 HIGH
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
CVSS 8.1
CVE-2026-33937 CRITICAL
Handlebars.js has JavaScript Injection via AST Type Confusion
CVSS 9.8
Details
Vulnerabilities 745