CWE-843— Access of Resource Using Incompatible Type (Type Confusion)
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.— MITRE CWE catalog
842 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-843page 10 of 17
- CVE-2023-42074HIGHCVSS 7.8EG 7.82024-05-03
PDF-XChange Editor addScript Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit …
- CVE-2023-42102HIGHCVSS 7.8EG 7.82024-05-03
Ashlar-Vellum Cobalt AR File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required t…
- CVE-2023-42105HIGHCVSS 7.8EG 7.82024-05-03
Ashlar-Vellum Cobalt AR File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required t…
- CVE-2023-42464CRITICALCVSS 9.8EG 9.82023-09-20
A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, one encoded data structure is a key-value style dictionary where the keys are character st…
- CVE-2023-43154CRITICALCVSS 9.8EG 9.82023-09-27
In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the admini…
- CVE-2023-4352HIGHCVSS 8.8EG 8.82023-08-15
Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-44094MEDIUMCVSS 5.3EG 5.32023-10-11
Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.
- CVE-2023-44108HIGHCVSS 7.5EG 7.52023-10-11
Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.
- CVE-2023-46705MEDIUMCVSS 5.5EG 6.22023-11-20
in OpenHarmony v3.2.2 and prior versions allow a local attacker causes system information leak through type confusion.
- CVE-2023-46842MEDIUMCVSS 6.5EG 6.52024-05-16
Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to pass 32-bit-mode hypercall arguments to values outside of the range 32-bit code would be ab…
- CVE-2023-4762CRITICALCVSS 8.8EG 9.0⚠ KEV2023-09-05
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-48694CRITICALCVSS 9.8EG 9.82023-12-05
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference and type confusion vulnerabilities …
- CVE-2023-49602LOWCVSS 2.9EG 2.92024-03-04
in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.
- CVE-2023-50433MEDIUMCVSS 6.5EG 6.52024-04-29
marshall in dhcp_packet.c in simple-dhcp-server through ec976d2 allows remote attackers to cause a denial of service by sending a malicious DHCP packet. The crash is caused by a type confusion bug that results in a large memory allocation;…
- CVE-2023-51426HIGHCVSS 7.1EG 7.12023-12-29
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
- CVE-2023-51427HIGHCVSS 7.1EG 7.12023-12-29
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
- CVE-2023-51428HIGHCVSS 7.1EG 7.12023-12-29
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
- CVE-2023-51560HIGHCVSS 7.8EG 7.82024-05-03
Foxit PDF Reader Annotation Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit thi…
- CVE-2023-5346HIGHCVSS 8.8EG 8.82023-10-05
Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-6045HIGHCVSS 7.8EG 7.82023-11-20
in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through type confusion.
- CVE-2023-6348HIGHCVSS 8.8EG 8.82023-11-29
Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-6702HIGHCVSS 8.8EG 8.82023-12-14
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-6939MEDIUMCVSS 5.5EG 5.52023-12-29
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause denial of service.
- CVE-2024-0042HIGHCVSS 7.8EG 7.82024-05-07
In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM content protection with no additional execution privileges needed. User interaction is not neede…
- CVE-2024-0518HIGHCVSS 8.8EG 8.82024-01-16
Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-10230HIGHCVSS 8.8EG 8.82024-10-22
Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-10231HIGHCVSS 8.8EG 8.82024-10-22
Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-11344HIGHCVSS 7.3EG 7.32025-02-13
A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
- CVE-2024-11346HIGHCVSS 7.3EG 7.32025-02-13
: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Resource Injection.This issue affects CX, XC, CS, et. Al.: from 001.001:0 th…
- CVE-2024-11395HIGHCVSS 8.8EG 8.82024-11-19
Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-11507HIGHCVSS 7.8EG 7.82024-11-22
IrfanView DXF File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulner…
- CVE-2024-11508HIGHCVSS 7.8EG 7.82024-11-22
IrfanView DXF File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulner…
- CVE-2024-12053HIGHCVSS 8.8EG 8.82024-12-03
Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-12381HIGHCVSS 8.8EG 8.82024-12-12
Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-12692HIGHCVSS 8.8EG 8.82024-12-18
Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-12834HIGHCVSS 7.8EG 7.82024-12-30
Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interact…
- CVE-2024-12836HIGHCVSS 7.8EG 7.82024-12-30
Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interact…
- CVE-2024-13047HIGHCVSS 7.8EG 7.82024-12-30
Ashlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required t…
- CVE-2024-13049HIGHCVSS 7.8EG 7.82024-12-30
Ashlar-Vellum Cobalt XE File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required t…
- CVE-2024-13169HIGHCVSS 7.8EG 7.82025-01-14
An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.
- CVE-2024-13275MEDIUMCVSS 5.3EG 5.32025-01-09
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This issue affects Security Kit: from 0.0.0 before 2.0.3.
- CVE-2024-1847HIGHCVSS 7.8EG 7.82024-02-28
Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings fr…
- CVE-2024-1848HIGHCVSS 7.8EG 7.82024-03-22
Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in SOLIDWORKS D…
- CVE-2024-1938HIGHCVSS 8.8EG 8.82024-02-29
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-1939HIGHCVSS 8.8EG 8.82024-02-29
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-20010MEDIUMCVSS 6.7EG 6.72024-02-05
In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0835…
- CVE-2024-20012MEDIUMCVSS 6.7EG 6.72024-02-05
In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0835…
- CVE-2024-20078CRITICALCVSS 9.8EG 9.82024-07-01
In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08737250; Issu…
- CVE-2024-20106MEDIUMCVSS 6.7EG 6.72024-11-04
In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0896050…
- CVE-2024-20662MEDIUMCVSS 4.9EG 4.92024-01-09
Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability
Map vulnerabilities like CWE-843 to your infrastructure
EchelonGraph correlates every CVE — across CWE-843 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →