CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

847 vulnerabilities with CWE-843
CVE-2023-32664 HIGH
Foxit PDF Reader 12.1.2.15332 - Remote Code Execution via JavaScript checkThisBox Method
CVSS 8.8
CVE-2023-36887 HIGH
Microsoft Edge Chromium < 114.0.1823.82 - Remote Code Execution via Type Confusion
CVSS 7.8
CVE-2023-38199 CRITICAL
coreruleset 3.3.4 - Info Disclosure
CVSS 9.8
CVE-2023-35356 HIGH
Windows 10 1607-22H2, Windows 11 21H2-22H2, Windows Server 2016-2022 - Privilege Escalation via Type Confusion
CVSS 7.8
CVE-2023-35297 HIGH
Windows Pragmatic General Multicast - Remote Code Execution via Type Confusion
CVSS 8.1
CVE-2023-37376 HIGH
Siemens Tecnomatix Plant Simulation Remote Code Execution via STP File Parsing
CVSS 7.8
CVE-2023-2234 MEDIUM
Zephyr < 3.3.0 - Remote Code Execution via Union Variant Confusion
CVSS 6.8
CVE-2023-20768 MEDIUM
Android - Local Privilege Escalation via Type Confusion in ion
CVSS 6.7
CVE-2023-3420 HIGH
Google Chrome < 114.0.5735.198 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
CVE-2023-32439 HIGH KEV
Safari < 16.5.1 - Remote Code Execution via Type Confusion
CVSS 8.8
CVE-2023-27930 HIGH
iPadOS < 16.5 - Type Confusion leading to Arbitrary Code Execution with Kernel Privileges
CVSS 7.8
CVE-2023-3022 MEDIUM
Linux Kernel < 5.1 - Denial of Service via IPv6 fib6_rule_lookup Type Confusion
CVSS 5.5
CVE-2023-3216 HIGH
Google Chrome < 114.0.5735.133 - Remote Code Execution via V8 Type Confusion
CVSS 8.8
CVE-2023-20747 MEDIUM
iot-yocto - Local Denial of Service via Type Confusion in vcu
CVSS 4.4
CVE-2023-3079 HIGH KEV
Google Chrome <114.0.5735.110 - Heap Corruption
CVSS 8.8
CVE-2023-28162 HIGH
Firefox < 111.0 and Firefox ESR < 102.9 - Type Confusion in AudioWorklet Implementation
CVSS 8.8
CVE-2023-2936 HIGH
Google Chrome < 114.0.5735.90 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
CVE-2023-2935 HIGH
Google Chrome < 114.0.5735.90 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
CVE-2023-24599 MEDIUM
OX App Suite <7.10.6-rev37 - Privilege Escalation
CVSS 4.3
CVE-2023-25933 CRITICAL
Facebook Hermes - Remote Code Execution via TypedArray Type Confusion
CVSS 9.8
CVE-2023-23557 CRITICAL
Facebook Hermes < 2023-01-10 - Remote Code Execution via Type Confusion
CVSS 9.8
CVE-2023-2724 HIGH
Google Chrome < 113.0.5672.126 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
CVE-2023-20673 MEDIUM
mediatek iot_yocto - Local Privilege Escalation via Type Confusion in vcu
CVSS 6.7
CVE-2023-24944 MEDIUM
Windows Bluetooth - Info Disclosure
CVSS 6.5
CVE-2023-24823 CRITICAL
RIOT-OS <2022.10 - Memory Corruption
CVSS 9.8
Details
Vulnerabilities 847