CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

847 vulnerabilities with CWE-843
CVE-2024-40676 HIGH
Android - Local Privilege Escalation via Confused Deputy in AccountManagerService
CVSS 7.7
CVE-2024-54507 MEDIUM
iPadOS < 18.2 - Authenticated Out-of-bounds Read via Type Confusion
CVSS 5.5
CVE-2024-13169 HIGH
Ivanti Endpoint Manager < 2022 SU6 - Authenticated Privilege Escalation via Out-of-bounds Read
CVSS 7.8
CVE-2024-13275 MEDIUM
Drupal Security Kit < 2.0.3 - Denial of Service via Type Confusion
CVSS 5.3
CVE-2024-13049 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via XE File Parsing Type Confusion
CVSS 7.8
CVE-2024-13047 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via CO File Parsing Type Confusion
CVSS 7.8
CVE-2024-12836 HIGH
Delta Electronics DRASimuCAD < 1.02.00.00 - Remote Code Execution via STP File Parsing Type Confusion
CVSS 7.8
CVE-2024-12834 HIGH
Delta Electronics DRASimuCAD < 1.02.00.00 - Remote Code Execution via STP File Parsing Type Confusion
CVSS 7.8
CVE-2024-56522 HIGH
TCPDF < 6.8.0 - Type Confusion via Loose Hash Comparison
CVSS 7.5
CVE-2024-12692 HIGH
Google Chrome < 131.0.6778.204 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
CVE-2024-54524 MEDIUM
macOS < 15.2 - Unauthenticated Arbitrary File Access via File Handling Logic Issue
CVSS 5.5
CVE-2024-54505 HIGH
Safari < 18.2 - Type Confusion via Malicious Web Content
CVSS 8.8
CVE-2024-49119 HIGH
Windows Server RCE (2016, 2019, 2022, 2022 23H2, 2025)
CVSS 8.1
CVE-2024-12381 HIGH
Google Chrome < 131.0.6778.139 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
CVE-2024-12053 HIGH
Google Chrome < 131.0.6778.108 - Type Confusion in V8
CVSS 8.8
CVE-2024-11508 HIGH
IrfanView DXF File Parser - Type Confusion Code Execution
CVSS 7.8
CVE-2024-11507 HIGH
IrfanView DXF File Parser - Type Confusion Code Execution
CVSS 7.8
CVE-2024-11395 HIGH
Google Chrome <131.0.6778.85 - Heap Corruption
CVSS 8.8
CVE-2024-43498 CRITICAL
.NET and Visual Studio - Remote Code Execution via Type Confusion
CVSS 9.8
CVE-2024-20106 MEDIUM
Android - Local Privilege Escalation via m4u Bounds Check Bypass
CVSS 6.7
CVE-2024-10231 HIGH
Google Chrome <130.0.6723.69 - Heap Corruption
CVSS 8.8
CVE-2024-10230 HIGH
Google Chrome <130.0.6723.69 - Heap Corruption
CVSS 8.8
CVE-2024-49860 HIGH
Linux Kernel - Use-After-Free via ACPI _STR Method Return Type Validation
CVSS 7.1
CVE-2024-43596 MEDIUM
Microsoft Edge Chromium < 130.0.2849.46 - Remote Code Execution via Type Confusion
CVSS 6.5
CVE-2024-9859 HIGH
Google Chrome < 126.0.6478.126 - Remote Code Execution via WebAssembly Type Confusion
CVSS 8.8
Details
Vulnerabilities 847