CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

847 vulnerabilities with CWE-843
CVE-2023-21675 HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2022-50590 MEDIUM
SuiteCRM < 7.12.6 - Unauthenticated Type Confusion via DeleteAttachment Module Parameter
CVSS 5.3
CVE-2022-46706 HIGH
macOS < 11.6.5 - Remote Code Execution via Type Confusion
CVSS 7.8
CVE-2022-4912 HIGH
Google Chrome < 105.0.5195.52 - Type Confusion in MathML via Crafted HTML Page
CVSS 8.8
CVE-2022-48511 CRITICAL
Huawei EMUI - Use-After-Free in Audio PCM Driver Module
CVSS 9.8
CVE-2022-37377 HIGH
Foxit PDF Editor 11.1.1.53537 - Remote Code Execution via JavaScript Optimization Type Confusion
CVSS 7.8
CVE-2022-4205 MEDIUM
GitLab < 15.6.1, 15.5.5, 15.4.6 - Type Confusion via Hexadecimal Branch Name
CVSS 6.3
CVE-2022-20461 HIGH
Android - Local Privilege Escalation via Type Confusion in pinReplyNative
CVSS 7.8
CVE-2022-25721 MEDIUM
Qualcomm AQT1000 Firmware - Memory Corruption via Video Driver Type Confusion
CVSS 6.7
CVE-2022-42856 HIGH KEV
Safari < 16.2 - Remote Code Execution via Type Confusion
CVSS 8.8
CVE-2022-42841 HIGH
macOS 11.0-11.7.1 - Remote Code Execution via Type Confusion
CVSS 7.8
CVE-2022-4262 HIGH KEV
Google Chrome < 108.0.5359.94 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
CVE-2022-4174 HIGH
Google Chrome < 108.0.5359.71 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
CVE-2022-3903 MEDIUM
Linux Kernel - Denial of Service via Infrared Transceiver USB Driver
CVSS 4.6
CVE-2022-3889 HIGH
Google Chrome <107.0.5304.106 - Heap Corruption
CVSS 8.8
CVE-2022-3723 HIGH KEV
Google Chrome < 107.0.5304.87 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
CVE-2022-3652 HIGH
Google Chrome < 107.0.5304.62 - Type Confusion in V8
CVSS 8.8
CVE-2022-42823 HIGH
Safari < 16.1 - Remote Code Execution via Type Confusion
CVSS 8.8
CVE-2022-3315 HIGH
Google Chrome <106.0.5249.62 - Heap Corruption
CVSS 8.8
CVE-2022-32915 HIGH
macOS < 12.6.3 - Type Confusion Leading to Kernel Code Execution
CVSS 7.8
CVE-2022-3676 MEDIUM
Eclipse Openj9 < 0.35.0 - Type Confusion via Interface Call Inlining
CVSS 6.5
CVE-2022-41033 HIGH KEV
Windows COM+ Event System Service - Privilege Escalation
CVSS 7.8
CVE-2022-32814 HIGH
iPadOS < 15.6 - Type Confusion Leading to Arbitrary Code Execution with Kernel Privileges
CVSS 7.8
CVE-2022-2971 HIGH
libiec61850 < 1.5.0 - Denial of Service via Type Confusion
CVSS 8.6
CVE-2022-34709 MEDIUM
Windows Defender Credential Guard - Security Feature Bypass via Type Confusion
CVSS 6.0
Details
Vulnerabilities 847