CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

788 vulnerabilities with CWE-843
CVE-2026-40683 HIGH
OpenStack Keystone <25.0.1 - Auth Bypass
CVSS 7.7
CVE-2026-26162 HIGH
Windows OLE Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-20806 MEDIUM
Windows COM Server Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-39956 MEDIUM
jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure
CVSS 6.1
CVE-2026-40446 MEDIUM
Samsung Open Source Escargot 97e8115ab1110bc502b4b5e4a0c689a71520d335 - Type Confusion
CVSS 6.9
CVE-2026-25204 MEDIUM
Samsung Open Source Escargot - Denial of Service via Deserialization of Untrusted Data
CVSS 6.2
CVE-2026-5496 HIGH
Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-5914 HIGH
Google Chrome <147.0.7727.55 - Memory Corruption
CVSS 8.8
CVE-2026-5871 HIGH
Google Chrome <147.0.7727.55 - Type Confusion
CVSS 8.8
CVE-2026-5865 HIGH
Google Chrome <147.0.7727.55 - Type Confusion
CVSS 8.8
CVE-2026-27144 HIGH
Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
CVSS 7.1
CVE-2026-34379 HIGH
OpenEXR DWA/DWAB LossyDctDecoder - Misaligned Write
CVSS 7.1
CVE-2026-35541 MEDIUM
Roundcube Webmail <1.5.14 - Auth Bypass
CVSS 4.2
CVE-2026-5360 LOW
Free5GC aper type confusion
CVSS 3.7
CVE-2026-34595 MEDIUM
Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value
CVSS 4.3
CVE-2026-33940 HIGH
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
CVSS 8.1
CVE-2026-33938 HIGH
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
CVSS 8.1
CVE-2026-33937 CRITICAL
Handlebars.js has JavaScript Injection via AST Type Confusion
CVSS 9.8
CVE-2026-28822 MEDIUM
iOS and iPadOS < 26.4 - Type Confusion
CVSS 6.2
CVE-2026-4702 CRITICAL
JIT miscompilation in the JavaScript Engine component
CVSS 9.8
CVE-2026-4698 CRITICAL
JIT miscompilation in the JavaScript Engine: JIT component
CVSS 9.8
CVE-2026-32701 HIGH
Qwik has array method pollution in FormData processing, allowing type confusion and DoS
CVSS 7.5
CVE-2026-33055 HIGH
tar-rs incorrectly ignores PAX size headers if header size is nonzero
CVSS 8.1
CVE-2026-4457 HIGH
Google Chrome <146.0.7680.153 - Memory Corruption
CVSS 8.8
CVE-2026-31968 HIGH
HTSlib CRAM decoder vulnerable to buffer overflow
CVSS 8.1
Details
Vulnerabilities 788