CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

789 vulnerabilities with CWE-843
CVE-2021-40061 HIGH
Huawei EMUI - Type Confusion in Bastet Module
CVSS 7.5
CVE-2021-46463 CRITICAL
njs < 0.7.1 - Control Flow Hijack via Type Confusion in njs_promise_perform_then()
CVSS 9.8
CVE-2021-46152 HIGH
Simcenter Femap V2020.2-V2021.1 - Code Injection
CVSS 7.8
CVE-2021-34866 HIGH
Linux Kernel 5.8-5.14-rc3 - Local Privilege Escalation via eBPF Program Type Confusion
CVSS 7.8
CVE-2021-24044 CRITICAL
Hermes < 0.10.0 - Type Confusion via Invalid JavaScript Await/Yield
CVSS 9.8
CVE-2021-44647 MEDIUM
Lua >= 5.4.3 - Denial of Service via Type Confusion in funcnamefromcode
CVSS 5.5
CVE-2021-40037 MEDIUM
HarmonyOS < 2.0 - Denial of Service via MPTCP Type Confusion
CVSS 5.5
CVE-2021-39987 HIGH
HarmonyOS < 2.0 - Denial of Service in HwNearbyMain Module
CVSS 7.5
CVE-2021-4078 HIGH
Google Chrome <96.0.4664.93 - Heap Corruption
CVSS 8.8
CVE-2021-4061 HIGH
Google Chrome <96.0.4664.93 - Heap Corruption
CVSS 8.8
CVE-2021-4056 HIGH
Google Chrome <96.0.4664.93 - Heap Corruption
CVSS 8.8
CVE-2021-38012 HIGH
Google Chrome <96.0.4664.45 - Heap Corruption
CVSS 8.8
CVE-2021-38007 HIGH
Google Chrome <96.0.4664.45 - Heap Corruption
CVSS 8.8
CVE-2021-24045 CRITICAL
Facebook Hermes < 0.10.0 - Type Confusion via 'typeof' Operator
CVSS 9.8
CVE-2021-38001 HIGH
Google Chrome <95.0.4638.69 - Heap Corruption
CVSS 8.8
CVE-2021-41190 LOW
OCI Distribution Spec <1.0.0 - Info Disclosure
CVSS 3.0
CVE-2021-40872 HIGH
Softing Industrial Automation uaToolkit Embedded <1.40 - DoS
CVSS 7.5
CVE-2021-40871 HIGH
Softing Industrial Automation OPC UA C++ SDK <5.66 - DoS
CVSS 7.5
CVE-2021-31344 MEDIUM
Siemens Capital VSTAR - ICMP Echo Reply Spoofing via Fake IP Options
CVSS 5.3
CVE-2021-23820 MEDIUM
json-pointer < 0.6.2 - Type Confusion via Array Pointer Components
CVSS 5.6
CVE-2021-23807 MEDIUM
jsonpointer < 5.0.0 - Prototype Pollution Bypass via Array Pointer Components
CVSS 5.6
CVE-2021-23624 MEDIUM
dotty < 0.1.2 - Type Confusion via Array Path Parameter
CVSS 5.6
CVE-2021-23509 MEDIUM
json-ptr < 3.0.0 - Type Confusion via Array Keys in Pointer Parameter
CVSS 5.6
CVE-2021-23472 LOW
bootstrap-table < 1.19.1 - Type Confusion in escapeHTML Function
CVSS 3.1
CVE-2021-30818 HIGH
Apple OSes and Safari - Code Execution via Malicious Web Content
CVSS 8.8
Details
Vulnerabilities 789