CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

789 vulnerabilities with CWE-843
CVE-2020-35636 CRITICAL
CGAL - Out-of-bounds Read in Nef Polygon Parser
CVSS 9.8
CVE-2020-27257 HIGH
Omron CX-One < 4.60 - Local Arbitrary Code Execution via Type Confusion
CVSS 7.8
CVE-2020-36229 HIGH
OpenLDAP < 2.4.57 - Denial of Service via X.509 DN Parsing in ad_keystring
CVSS 7.5
CVE-2020-26990 HIGH
Siemens JT2Go and Teamcenter Visualization < 13.1.0.1 - Remote Code Execution via ASM File Parsing
CVSS 8.8
CVE-2020-26980 HIGH
Siemens JT2Go and Teamcenter Visualization < 13.1.0 - Remote Code Execution via JT File Parsing
CVSS 8.8
CVE-2020-27293 HIGH
Delta Electronics CNCSoft-B <1.0.0.2 - RCE
CVSS 7.8
CVE-2020-16015 HIGH
Google Chrome < 87.0.4280.66 - Remote Code Execution via WASM Type Confusion
CVSS 8.8
CVE-2020-6656 MEDIUM
Eaton easySoft 7.00-7.20 - Remote Code Execution via Malformed .E70 File Parsing
CVSS 5.8
CVE-2020-13547 HIGH
Foxit Reader 10.1.0.37527 - Type Confusion in JavaScript Engine
CVSS 8.8
CVE-2020-16103 HIGH
Gallagher Command Centre < 8.00 - Remote Code Execution via Type Confusion
CVSS 8.8
CVE-2020-27932 HIGH KEV
Apple iCloud < 11.5 - Remote Code Execution via Type Confusion
CVSS 7.8
CVE-2020-25661 HIGH
Red Hat Enterprise Linux - Remote Code Execution or Denial of Service via Crafted L2CAP Packet
CVSS 7.5
CVE-2020-16009 HIGH KEV
CefSharp < 86.0.241 - Remote Code Execution via V8 Type Confusion
CVSS 8.8
CVE-2020-9948 HIGH
Safari < 14.0 - Remote Code Execution via Type Confusion
CVSS 8.8
CVE-2020-13341 MEDIUM
GitLab <13.2.10-13.4.2 - Privilege Escalation
CVSS 4.9
CVE-2020-6537 HIGH
Google Chrome < 84.0.4147.105 - Remote Code Execution via V8 Type Confusion
CVSS 8.8
CVE-2020-15965 HIGH
Google Chrome < 85.0.4183.121 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
CVE-2020-0336 MEDIUM
Android 11 - Local Privilege Escalation via SurfaceFlinger Type Confusion
CVSS 6.7
CVE-2020-25575 CRITICAL
failure < 0.1.8 - Type Confusion via Downcasting
CVSS 9.8
CVE-2020-1911 CRITICAL
Facebook Hermes < 0.4.3 and hermes-engine < 0.5.2 - Type Confusion via Prototype Chain Manipulation
CVSS 9.8
CVE-2020-25016 CRITICAL
rgb-rust < 0.8.20 - Memory Safety Violation via Struct Byte Manipulation
CVSS 9.1
CVE-2020-15638 HIGH
Foxit PhantomPDF and Reader < 10.0.0.35798 - Remote Code Execution via NodeProperties Type Confusion
CVSS 7.8
CVE-2020-15656 HIGH
Firefox < 79.0 and Firefox ESR < 78.1 - Type Confusion in JIT Optimizations
CVSS 8.8
CVE-2020-16229 HIGH
Advantech WebAccess HMI Designer < 2.1.9.31 - Remote Code Execution via Crafted Project File
CVSS 7.8
CVE-2020-6533 HIGH
Google Chrome < 84.0.4147.89 - Type Confusion in V8 via Crafted HTML Page
CVSS 8.8
Details
Vulnerabilities 789