CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

788 vulnerabilities with CWE-843
CVE-2026-44325 HIGH
free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Reflect.Set on incompatible types)
CVSS 7.5
CVE-2026-44728 HIGH
Improper Control of Generation of Code when compiling specifically crafted malicious code with @babel/plugin-transform-modules-systemjs
CVSS 8.2
CVE-2026-9117 HIGH
Google Chrome < 148.0.7778.179 - Type Confusion in GFX via Crafted Video File
CVSS 7.5
CVE-2026-5946 HIGH
BIND 9.11.0-9.16.50, 9.18.0-9.18.48, 9.20.0-9.20.22, 9.21.0-9.21.21 - DoS via Non-IN DNS Message Handling
CVSS 7.5
CVE-2026-8570 MEDIUM
Google Chrome < 148.0.7778.168 - Type Confusion in V8
CVSS 6.5
CVE-2026-8554 LOW
Google Chrome < 148.0.7778.168 - Type Confusion in ANGLE via Crafted HTML Page
CVSS 3.1
CVE-2026-8540 HIGH
Google Chrome < 148.0.7778.168 - Remote Code Execution via V8 Type Confusion
CVSS 8.8
CVE-2026-40364 HIGH
Microsoft Word Remote Code Execution Vulnerability
CVSS 8.4
CVE-2026-35417 HIGH
Microsoft Windows 10 Version 1809 - Windows Win32k Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-34344 HIGH
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-8389 HIGH
JIT miscompilation in the JavaScript Engine: JIT component
CVSS 8.8
CVE-2026-28983 HIGH
iOS and iPadOS < 18.7.9 - Denial of Service via Type Confusion
CVSS 7.5
CVE-2026-7988 HIGH
Google Chrome < 148.0.7778.96 - Remote Code Execution via WebRTC Type Confusion
CVSS 8.8
CVE-2026-7927 HIGH
Google Chrome < 148.0.7778.96 - Remote Code Execution via Type Confusion in Runtime
CVSS 8.8
CVE-2026-7914 HIGH
Google Chrome < 148.0.7778.96 - Type Confusion in Accessibility
CVSS 8.3
CVE-2026-6210 HIGH
Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash
CVE-2026-43862 LOW
mutt < 2.3.2 - Type Confusion in IMAP GSSAPI Authentication
CVSS 3.7
CVE-2026-20451 MEDIUM
MediaTek chipset - Local Privilege Escalation via Type Confusion in slbc
CVSS 6.7
CVE-2026-7337 HIGH
Google Chrome <147.0.7727.138 - Type Confusion RCE
CVSS 8.8
CVE-2026-6732 MEDIUM
Libxml2: libxml2: denial of service via crafted xsd-validated document
CVSS 6.5
CVE-2026-31502 HIGH
team: fix header_ops type confusion with non-Ethernet ports
CVSS 7.8
CVE-2026-6363 HIGH
Google Chrome < 147.0.7727.101 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
CVE-2026-6307 HIGH
Google Chrome <147.0.7727.101 - Type Confusion
CVSS 8.8
CVE-2026-6301 HIGH
Google Chrome <147.0.7727.101 - Type Confusion
CVSS 8.8
CVE-2026-27298 HIGH
Adobe Framemaker | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)
CVSS 7.8
Details
Vulnerabilities 788