CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

789 vulnerabilities with CWE-843
CVE-2021-27038 HIGH
Autodesk Design Review 2011-2018 - Remote Code Execution via Malicious PDF File
CVSS 7.8
CVE-2021-22354 CRITICAL
Huawei Smartphone - Info Disclosure
CVSS 9.1
CVE-2021-33624 MEDIUM
Linux kernel <5.12.13 - Memory Corruption
CVSS 4.7
CVE-2021-32696 LOW
striptags < 3.2.0 - Cross-Site Scripting via Array-like Object Type Confusion
CVSS 3.7
CVE-2021-31476 HIGH
Foxit Reader < 10.1.3.37598 and PhantomPDF < 9.7.5.29616 - Remote Code Execution via XFA Template Handling
CVSS 7.8
CVE-2021-30551 HIGH KEV
Google Chrome <91.0.4472.101 - Heap Corruption
CVSS 8.8
CVE-2021-31480 HIGH
OpenText Brava! Desktop 16.6.3.84 - Remote Code Execution via DXF File Parsing
CVSS 7.8
CVE-2021-30517 HIGH
Google Chrome <90.0.4430.212 - Heap Corruption
CVSS 8.8
CVE-2021-30513 HIGH
Google Chrome <90.0.4430.212 - Heap Corruption
CVSS 8.8
CVE-2021-3320 MEDIUM
Zephyr 2.0.0-2.3.9 - Type Confusion in 802.15.4 ACK Frame Handling
CVSS 5.9
CVE-2021-31318 MEDIUM
Telegram < 7.1.0 - Type Confusion in LOTCompLayerItem Function via Animated Sticker
CVSS 5.5
CVE-2021-31317 MEDIUM
Telegram < 7.1.0 - Type Confusion in VDasher Constructor via Malicious Animated Sticker
CVSS 5.5
CVE-2021-29519 LOW
TensorFlow < 2.1.4 - Denial of Service via Type Confusion in SparseCross API
CVSS 2.5
CVE-2021-29513 LOW
TensorFlow < 2.1.4 - Type Confusion via Non-Numeric Tensor Input
CVSS 2.5
CVE-2021-23908 LOW
Mercedes-Benz Headunit NTG6 MBUX - Remote Code Execution via HiQnet MultiSvSetAttributes Type Confusion
CVSS 2.9
CVE-2021-31461 HIGH
Foxit PhantomPDF and Reader - Remote Code Execution via app.media Object Type Confusion
CVSS 7.8
CVE-2021-21230 HIGH
Google Chrome <90.0.4430.93 - Heap Corruption
CVSS 8.8
CVE-2021-21224 HIGH KEV
Google Chrome < 90.0.4430.85 - Remote Code Execution via V8 Type Confusion
CVSS 8.8
CVE-2021-28468 HIGH
Raw Image Extension - Remote Code Execution via Type Confusion
CVSS 7.8
CVE-2021-1789 HIGH KEV
iPadOS < 14.4 - Remote Code Execution via Type Confusion
CVSS 8.8
CVE-2021-23954 HIGH
Firefox < 85.0 and Firefox ESR < 78.7 - Type Confusion via JavaScript Logical Assignment in Switch Statement
CVSS 8.8
CVE-2021-0352 MEDIUM
Android 10-11 - Memory Corruption via RT Regmap Driver Type Confusion
CVSS 4.4
CVE-2021-25177 HIGH
Open Design Alliance Drawings SDK <2021.11 - Crash
CVSS 7.8
CVE-2020-36460 HIGH
model_project/model < 2020-11-10 - Type Confusion in Shared Data Structure
CVSS 8.1
CVE-2020-22882 HIGH
Moddable < os200831 - Denial of Service via fxParserTree Type Confusion
CVSS 7.5
Details
Vulnerabilities 789