CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

789 vulnerabilities with CWE-843
CVE-2024-20678 HIGH
Microsoft Windows RPC Runtime - Remote Code Execution
CVSS 8.8
CVE-2024-30266 LOW
wasmtime 19.0.0 - Type Confusion via WebAssembly Module Execution
CVSS 3.3
CVE-2024-3298 HIGH
Dassault eDrawings SOLIDWORKS 2023-2024 - DWG/DXF Code Execution
CVSS 7.8
CVE-2024-30357 HIGH
Foxit PDF Editor and PDF Reader - Remote Code Execution via AcroForm Annotation Type Confusion
CVSS 7.8
CVE-2024-21834 LOW
OpenHarmony < 3.2.4 - Local Denial of Service via Type Confusion
CVSS 3.3
CVE-2024-2887 HIGH
Google Chrome < 123.0.6312.86 - Remote Code Execution via WebAssembly Type Confusion
CVSS 7.7
CVE-2024-1848 HIGH
SOLIDWORKS Desktop Release SOLIDWORKS 2024 SP0 - Heap-based Buffer Overflow in File Reading Procedure
CVSS 7.8
CVE-2024-27236 HIGH
Android - Local Privilege Escalation via Type Confusion in aoc_unlocked_ioctl
CVSS 8.4
CVE-2024-1939 HIGH
Google Chrome <122.0.6261.94 - Heap Corruption
CVSS 8.8
CVE-2024-1938 HIGH
Google Chrome <122.0.6261.94 - Remote Code Execution
CVSS 8.8
CVE-2024-1847 HIGH
SOLIDWORKS 2023-2024 - Multiple Memory Corruption Vulnerabilities in File Reading Procedure
CVSS 7.8
CVE-2024-21363 HIGH
Windows 10 1507-22H2 - Remote Code Execution in Microsoft Message Queuing
CVSS 7.8
CVE-2024-21357 HIGH
Windows 10 1507-22H2 - Remote Code Execution via Pragmatic General Multicast
CVSS 8.1
CVE-2024-20012 MEDIUM
Android - Local Privilege Escalation via Type Confusion in keyInstall
CVSS 6.7
CVE-2024-20010 MEDIUM
Android - Local Privilege Escalation via Type Confusion in keyInstall
CVSS 6.7
CVE-2024-23222 HIGH KEV
iPadOS < 16.7.5 - Remote Code Execution via Type Confusion
CVSS 8.8
CVE-2024-0518 HIGH
Google Chrome <120.0.6099.224 - Heap Corruption
CVSS 8.8
CVE-2024-20662 MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022, 2022 23H2 - Information Disclosure via OCSP Type Confusion
CVSS 4.9
CVE-2023-31323 HIGH
AMD Secure Processor - Memory Corruption
CVE-2023-31322 HIGH
AMD Radeon RX 7000 Series Graphics Products - Type Confusion in ASP via Malformed RAS TA Argument
CVSS 8.7
CVE-2023-46842 MEDIUM
Xen >= 3.2.0 - Denial of Service via Hypercall Continuation Type Confusion
CVSS 6.5
CVE-2023-51560 HIGH
Foxit PDF Editor < 10.1.12.37872 & PDF Reader < 2023.2.0.21408 - RCE via Annotation Type Confusion
CVSS 7.8
CVE-2023-42105 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via AR File Parsing Type Confusion
CVSS 7.8
CVE-2023-42102 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via AR File Parsing Type Confusion
CVSS 7.8
CVE-2023-42074 HIGH
PDF-XChange Editor - Remote Code Execution via addScript Type Confusion
CVSS 7.8
Details
Vulnerabilities 789