CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

788 vulnerabilities with CWE-843
CVE-2025-21279 MEDIUM
Microsoft Edge Chromium < 133.0.3065.51 - Remote Code Execution via Type Confusion
CVSS 6.5
CVE-2025-0147 HIGH
Zoom Workplace App <6.2.10 - Privilege Escalation
CVSS 8.8
CVE-2025-24137 HIGH
iPadOS < 17.7.4 - Type Confusion
CVSS 8.0
CVE-2025-24129 HIGH
iPadOS < 18.3 - Type Confusion
CVSS 7.5
CVE-2025-22153 HIGH
CPython <3.13.2, RestrictedPython <8.0 - RCE
CVSS 7.9
CVE-2025-21356 HIGH
Microsoft Office Visio - Remote Code Execution via Type Confusion
CVSS 7.8
CVE-2025-21326 HIGH
Windows Server 2022 23H2 < 10.0.25398.1369 and Windows Server 2025 < 10.0.26100.2894 - Remote Code Execution
CVSS 7.8
CVE-2025-21225 MEDIUM
Windows Server 2016/2019/2022/2025 RD Gateway DoS
CVSS 5.9
CVE-2025-22151 LOW
Strawberry GraphQL <0.257.0 - Type Confusion
CVSS 3.7
CVE-2025-0291 HIGH
Google Chrome <131.0.6778.264 - RCE
CVSS 8.8
CVE-2024-49196 HIGH
Samsung Exynos 1480 and 2400 Firmware - Denial of Service via GPU Type Confusion
CVSS 7.5
CVE-2024-58253 LOW
obfstr < 0.4.4 - Type Confusion via Invalid UTF-8 Conversion
CVSS 2.9
CVE-2024-53427 HIGH
jqlang/jq < 1.7.1 - Stack-Based Buffer Overflow via NaN Handling in decNumberCopy
CVSS 8.1
CVE-2024-37603 MEDIUM
Mercedes-Benz NTG6 Head Unit - Denial of Service via User Data Import/Export Type Confusion
CVSS 4.6
CVE-2024-11346 HIGH
Lexmark International CX XC CS et Al - Type Confusion
CVSS 7.3
CVE-2024-11344 HIGH
Lexmark Printer PostScript Interpreter - Type Confusion Code Execution
CVSS 7.3
CVE-2024-40676 HIGH
Android - Local Privilege Escalation via Confused Deputy in AccountManagerService
CVSS 7.7
CVE-2024-54507 MEDIUM
iPadOS < 18.2 - Authenticated Out-of-bounds Read via Type Confusion
CVSS 5.5
CVE-2024-13169 HIGH
Ivanti Endpoint Manager < 2022 SU6 - Authenticated Privilege Escalation via Out-of-bounds Read
CVSS 7.8
CVE-2024-13275 MEDIUM
Drupal Security Kit < 2.0.3 - Denial of Service via Type Confusion
CVSS 5.3
CVE-2024-13049 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via XE File Parsing Type Confusion
CVSS 7.8
CVE-2024-13047 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via CO File Parsing Type Confusion
CVSS 7.8
CVE-2024-12836 HIGH
Delta Electronics DRASimuCAD < 1.02.00.00 - Remote Code Execution via STP File Parsing Type Confusion
CVSS 7.8
CVE-2024-12834 HIGH
Delta Electronics DRASimuCAD < 1.02.00.00 - Remote Code Execution via STP File Parsing Type Confusion
CVSS 7.8
CVE-2024-56522 HIGH
TCPDF < 6.8.0 - Type Confusion via Loose Hash Comparison
CVSS 7.5
Details
Vulnerabilities 788