CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

791 vulnerabilities with CWE-843
CVE-2020-11603 CRITICAL
Android P(9.0) and Q(10.0) - Type Confusion in MLDAP Trustlet
CVSS 9.8
CVE-2020-3901 HIGH
iCloud < 10.9.3 - Remote Code Execution via Type Confusion
CVSS 8.8
CVE-2020-3897 HIGH
iCloud < 7.18 - Remote Code Execution via Type Confusion
CVSS 8.8
CVE-2020-6418 HIGH KEV
Google Chrome <80.0.3987.122 - Heap Corruption
CVSS 8.8
CVE-2020-6383 HIGH
Google Chrome <80.0.3987.116 - Heap Corruption
CVSS 8.8
CVE-2020-3853 HIGH
iPadOS < 13.3.1 - Type Confusion leading to Privilege Escalation
CVSS 7.8
CVE-2020-3757 HIGH
Adobe Flash Player <32.0.0.255 - RCE
CVSS 8.8
CVE-2020-6382 HIGH
Google Chrome <80.0.3987.87 - Heap Corruption
CVSS 8.8
CVE-2019-25010 CRITICAL
failure crate <2019-11-13 - Code Injection
CVSS 9.8
CVE-2019-17639 MEDIUM
Eclipse OpenJ9 < 0.21 - Type Confusion via System.arraycopy
CVSS 5.3
CVE-2019-8252 MEDIUM
Adobe Acrobat and Reader DC - Type Confusion leading to Information Disclosure
CVSS 5.5
CVE-2019-8251 MEDIUM
Adobe Acrobat and Reader DC - Type Confusion leading to Information Disclosure
CVSS 5.5
CVE-2019-8250 HIGH
Adobe Acrobat and Reader DC < 15.006.30498, 15.008.20082-19.012.20035 - Type Confusion leading to Remote Code Execution
CVSS 7.8
CVE-2019-8249 HIGH
Adobe Acrobat and Reader DC < 19.012.20035 - Type Confusion leading to Remote Code Execution
CVSS 7.8
CVE-2019-15792 HIGH
Linux Kernel shiftfs - Use-After-Free via fdget Private Data Type Confusion
CVSS 7.1
CVE-2019-20589 CRITICAL
Samsung Android O(8.x) and P(9.0) - Arbitrary Code Execution via SKPM Trustlet Type Confusion
CVSS 9.8
CVE-2019-20588 CRITICAL
Samsung Android O(8.x) and P(9.0) - Arbitrary Code Execution via SEM Trustlet Type Confusion
CVSS 9.8
CVE-2019-20587 CRITICAL
Android O(8.1) and P(9.0) - Type Confusion in MLDAP Trustlet
CVSS 9.8
CVE-2019-20586 CRITICAL
Android O(8.1) and P(9.0) - Type Confusion in FINGERPRINT Trustlet
CVSS 9.8
CVE-2019-20585 CRITICAL
Samsung Android O(8.x) and P(9.0) - Arbitrary Code Execution via SEC_FR Trustlet Type Confusion
CVSS 9.8
CVE-2019-20584 CRITICAL
Android O(8.x) and P(9.0) - Remote Code Execution via HDCP Trustlet Type Confusion
CVSS 9.8
CVE-2019-20583 CRITICAL
Android O(8.x) and P(9.0) - Arbitrary Code Execution via EXT_FR Trustlet Type Confusion
CVSS 9.8
CVE-2019-20571 CRITICAL
Android - Type Confusion in WVDRM Trustlet
CVSS 9.8
CVE-2019-17026 HIGH KEV
Firefox < 72.0.1 and Firefox ESR < 68.4.1 - Type Confusion in IonMonkey JIT Compiler
CVSS 8.8
CVE-2019-7131 CRITICAL
Adobe Acrobat and Reader <2019.010.20064 - RCE
CVSS 9.8
Details
Vulnerabilities 791