CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

791 vulnerabilities with CWE-843
CVE-2019-9791 CRITICAL
Thunderbird <60.6-Firefox <66 - Memory Corruption
CVSS 9.8
CVE-2019-0810 HIGH
ChakraCore < 1.11.8 - Remote Code Execution via Type Confusion
CVSS 7.5
CVE-2019-0752 HIGH KEV
Internet Explorer - Memory Corruption
CVSS 7.5
CVE-2019-10231 CRITICAL
Teclib GLPI < 9.4.1.1 - Authentication Bypass via PHP Type Juggling in Auth::checkPassword()
CVSS 9.8
CVE-2019-6215 HIGH
Safari < 12.0.3 - Remote Code Execution via Type Confusion
CVSS 8.8
CVE-2019-6214 HIGH
iPhone OS < 12.1.3, macOS < 10.14.3, tvOS < 12.1.2, watchOS < 5.1.3 - Sandbox Escape via Type Confusion
CVSS 8.6
CVE-2019-6984 MEDIUM
Foxit 3D Plugin Beta <9.4.0.16807 - Memory Corruption
CVSS 6.5
CVE-2018-9471 HIGH
Android - Local Privilege Escalation via NanoAppFilter Deserialization Type Confusion
CVSS 7.8
CVE-2018-9339 HIGH
Android - Local Privilege Escalation via Parcel Type Confusion
CVSS 7.8
CVE-2018-6122 HIGH
Google Chrome <66.0.3359.139 - Heap Corruption
CVSS 8.8
CVE-2018-19027 HIGH
CX-One <= 4.50 and CX-Protocol <= 2.0 - Remote Code Execution via Crafted Project File
CVSS 7.8
CVE-2018-17685 HIGH
Foxit PhantomPDF and Reader < 9.2.0.9297 - Remote Code Execution via PDF Type Confusion
CVSS 8.8
CVE-2018-19019 HIGH
CX-Supervisor < 3.42 - Remote Code Execution via Crafted Project File
CVSS 7.3
CVE-2018-14317 HIGH
Foxit Reader < 9.1.0.5096 - Remote Code Execution via PDF Processing Type Confusion
CVSS 8.8
CVE-2018-8384 HIGH
ChakraCore < 1.10.2 - Remote Code Execution via Type Confusion
CVSS 7.5
CVE-2018-14313 HIGH
Foxit Reader and PhantomPDF < 9.1.0.5096 - Remote Code Execution via PDF Type Confusion
CVSS 8.8
CVE-2018-14311 HIGH
Foxit Reader and PhantomPDF < 9.1.0.5096 - Remote Code Execution via XFA Event Handling
CVSS 8.8
CVE-2018-14287 HIGH
Foxit Reader and PhantomPDF < 9.1.0.5096 - Remote Code Execution via instanceManager.nodes.append Type Confusion
CVSS 8.8
CVE-2018-14286 HIGH
Foxit Reader and PhantomPDF < 9.1.0.5096 - Remote Code Execution via mailDoc Function Type Confusion
CVSS 8.8
CVE-2018-14285 HIGH
Foxit Reader and PhantomPDF < 9.1.0.5096 - Remote Code Execution via oneOfChild Attribute Type Confusion
CVSS 8.8
CVE-2018-14279 HIGH
Foxit Reader and PhantomPDF < 9.1.0.5096 - Remote Code Execution via resetForm Method Type Confusion
CVSS 8.8
CVE-2018-14278 HIGH
Foxit Reader and PhantomPDF < 9.1.0.5096 - Remote Code Execution via getPageNumWords Type Confusion
CVSS 8.8
CVE-2018-14277 HIGH
Foxit Reader and PhantomPDF < 9.1.0.5096 - Remote Code Execution via mailDoc Method Type Confusion
CVSS 8.8
CVE-2018-14276 HIGH
Foxit Reader and PhantomPDF < 9.1.0.5096 - Remote Code Execution via submitForm Type Confusion
CVSS 8.8
CVE-2018-14275 HIGH
Foxit Reader and PhantomPDF < 9.1.0.5096 - Remote Code Execution via spawnPageFromTemplate Type Confusion
CVSS 8.8
Details
Vulnerabilities 791