CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

789 vulnerabilities with CWE-843
CVE-2023-36578 HIGH
Microsoft Windows MSMQ - Remote Code Execution via Type Confusion
CVSS 7.3
CVE-2023-5346 HIGH
Google Chrome < 117.0.5938.149 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
CVE-2023-43154 CRITICAL
Macs CMS 1.1.4f - Authentication Bypass via PHP Type Confusion in isValidLogin()
CVSS 9.8
CVE-2023-42464 CRITICAL
Netatalk 3.1.x < 3.1.17 - Type Confusion in Spotlight RPC Packet Parsing
CVSS 9.8
CVE-2023-38074 HIGH
Siemens JT2Go < 14.3.0.1 - Remote Code Execution via WRL File Parsing
CVSS 7.8
CVE-2023-38073 HIGH
Siemens JT2Go < 14.3.0.1 - Remote Code Execution via WRL File Parsing
CVSS 7.8
CVE-2023-4762 HIGH KEV
Google Chrome < 116.0.5845.179 - Remote Code Execution via V8 Type Confusion
CVSS 8.8
CVE-2023-4352 HIGH
Google Chrome <116.0.5845.96 - Heap Corruption
CVSS 8.8
CVE-2023-32358 HIGH
iPadOS 16.0-16.3 - Remote Code Execution via Type Confusion
CVSS 8.8
CVE-2023-21287 CRITICAL
Android - Remote Code Execution via Type Confusion
CVSS 9.8
CVE-2023-28575 MEDIUM
Qualcomm Firmware - Type Confusion in cam_get_device_priv
CVSS 6.7
CVE-2023-4194 MEDIUM
Linux Kernel < 6.4 - Unauthorized Resource Access via TUN/TAP Socket UID Initialization
CVSS 5.5
CVE-2023-4070 HIGH
Google Chrome <115.0.5790.170 - RCE
CVSS 8.1
CVE-2023-4069 HIGH
Google Chrome <115.0.5790.170 - Heap Corruption
CVSS 8.8
CVE-2023-4068 HIGH
Google Chrome <115.0.5790.170 - RCE
CVSS 8.1
CVE-2023-28729 HIGH
Panasonic Control FPWIN Pro <7.6.0.3 - RCE
CVSS 7.8
CVE-2023-34967 MEDIUM
Samba < 4.16.11 - Denial of Service via mdssvc RPC Spotlight Type Confusion
CVSS 5.3
CVE-2023-32664 HIGH
Foxit PDF Reader 12.1.2.15332 - Remote Code Execution via JavaScript checkThisBox Method
CVSS 8.8
CVE-2023-36887 HIGH
Microsoft Edge Chromium < 114.0.1823.82 - Remote Code Execution via Type Confusion
CVSS 7.8
CVE-2023-38199 CRITICAL
coreruleset 3.3.4 - Info Disclosure
CVSS 9.8
CVE-2023-35356 HIGH
Windows 10 1607-22H2, Windows 11 21H2-22H2, Windows Server 2016-2022 - Privilege Escalation via Type Confusion
CVSS 7.8
CVE-2023-35297 HIGH
Windows Pragmatic General Multicast - Remote Code Execution via Type Confusion
CVSS 8.1
CVE-2023-37376 HIGH
Siemens Tecnomatix Plant Simulation Remote Code Execution via STP File Parsing
CVSS 7.8
CVE-2023-2234 MEDIUM
Zephyr < 3.3.0 - Remote Code Execution via Union Variant Confusion
CVSS 6.8
CVE-2023-20768 MEDIUM
Android - Local Privilege Escalation via Type Confusion in ion
CVSS 6.7
Details
Vulnerabilities 789