CWE-843— Access of Resource Using Incompatible Type (Type Confusion)
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.— MITRE CWE catalog
842 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-843page 11 of 17
- CVE-2024-20678HIGHCVSS 8.8EG 8.82024-04-09
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- CVE-2024-21357HIGHCVSS 8.1EG 8.12024-02-13
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- CVE-2024-21363HIGHCVSS 7.8EG 7.82024-02-13
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2024-21834LOWCVSS 3.3EG 3.32024-04-02
in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.
- CVE-2024-23222CRITICALCVSS 8.8EG 9.0⚠ KEV2024-01-23
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13…
- CVE-2024-24421CRITICALCVSS 9.8EG 9.82025-01-21
A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted NAS packet.
- CVE-2024-25575HIGHCVSS 8.8EG 8.82024-04-30
A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory …
- CVE-2024-26232HIGHCVSS 7.3EG 7.32024-04-09
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2024-27236HIGHCVSS 8.4EG 8.42024-03-11
In aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-2887HIGHCVSS 7.7EG 8.12024-03-26
Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-30034MEDIUMCVSS 5.5EG 5.52024-05-14
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
- CVE-2024-30266LOWCVSS 3.3EG 3.32024-04-04
wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, whe…
- CVE-2024-30357HIGHCVSS 7.8EG 7.82024-04-02
Foxit PDF Reader AcroForm Annotation Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to ex…
- CVE-2024-31071LOWCVSS 3.3EG 3.32024-07-02
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.
- CVE-2024-32057HIGHCVSS 7.8EG 7.82024-05-14
A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the cur…
- CVE-2024-32062HIGHCVSS 7.8EG 7.82024-05-14
A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the cur…
- CVE-2024-32063HIGHCVSS 7.8EG 7.82024-05-14
A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the cur…
- CVE-2024-32892HIGHCVSS 7.8EG 7.82024-06-13
In handle_init of goodix/main/main.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita…
- CVE-2024-32919HIGHCVSS 7.8EG 7.82024-06-13
In lwis_add_completion_fence of lwis_fence.c, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede…
- CVE-2024-32922HIGHCVSS 7.4EG 7.42024-06-13
In gpu_pm_power_on_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a logic error in the code. This could lead to local escalation of privilege to TEE with no additional execution privileges needed…
- CVE-2024-3298HIGHCVSS 7.8EG 7.82024-04-04
Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code w…
- CVE-2024-34391HIGHCVSS 8.1EG 8.12024-05-02
libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both …
- CVE-2024-34392HIGHCVSS 8.1EG 8.12024-05-02
libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes _wrap__xmlNode_nsDef_get()) on a grand-child of a node that refers to an entity. This vul…
- CVE-2024-34393HIGHCVSS 8.1EG 8.12024-05-02
libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both…
- CVE-2024-34394HIGHCVSS 8.1EG 8.12024-05-02
libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes XmlNode::get_local_namespaces()) on a grand-child of a node that refers to an entity. Th…
- CVE-2024-34742MEDIUMCVSS 5.5EG 5.52024-08-15
In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. U…
- CVE-2024-36278LOWCVSS 3.3EG 3.32024-07-02
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.
- CVE-2024-37603MEDIUMCVSS 4.6EG 5.12025-02-13
An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible type confusion exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the USB interface of the car …
- CVE-2024-37987HIGHCVSS 8.0EG 8.02024-07-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-38178CRITICALCVSS 7.5EG 9.0⚠ KEV2024-08-13
Scripting Engine Memory Corruption Vulnerability
- CVE-2024-38207MEDIUMCVSS 6.3EG 6.32024-08-23
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
- CVE-2024-38209HIGHCVSS 7.8EG 7.82024-08-22
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2024-38218HIGHCVSS 8.4EG 8.42024-08-12
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
- CVE-2024-38219MEDIUMCVSS 6.5EG 6.52024-08-12
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2024-4058HIGHCVSS 8.8EG 8.82024-05-01
Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2024-40676HIGHCVSS 7.7EG 7.72025-01-28
In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This could lead to local escalation of privilege with no additional execution pri…
- CVE-2024-40788MEDIUMCVSS 5.5EG 5.52024-07-29
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, wat…
- CVE-2024-40803HIGHCVSS 7.5EG 7.52024-07-29
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An attacker may be able to cause unexpected app termination.
- CVE-2024-43357HIGHCVSS 8.6EG 8.62024-08-15
ECMA-262 is the language specification for the scripting language ECMAScript. A problem in the ECMAScript (JavaScript) specification of async generators, introduced by a May 2021 spec refactor, may lead to mis-implementation in a way that …
- CVE-2024-43489MEDIUMCVSS 6.5EG 6.52024-09-19
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2024-43498CRITICALCVSS 9.8EG 9.82024-11-12
.NET and Visual Studio Remote Code Execution Vulnerability
- CVE-2024-43596MEDIUMCVSS 6.5EG 6.52024-10-17
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2024-45112HIGHCVSS 7.8EG 7.82024-09-13
Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the context of the current user. This issue occurs w…
- CVE-2024-47804MEDIUMCVSS 4.3EG 4.32024-10-02
If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and ear…
- CVE-2024-49119HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49196HIGHCVSS 7.5EG 7.52025-05-27
An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of Service.
- CVE-2024-4947CRITICALCVSS 9.6EG 9.6⚠ KEV2024-05-15
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-49860HIGHCVSS 7.1EG 7.12024-10-21
In the Linux kernel, the following vulnerability has been resolved: ACPI: sysfs: validate return type of _STR method Only buffer objects are valid return values of _STR. If something else is returned description_show() will access inval…
- CVE-2024-5158HIGHCVSS 8.1EG 8.82024-05-22
Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-5271HIGHCVSS 7.8EG 7.82024-05-30
Fuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a type confusion, which could result in arbitrary code execution.
Map vulnerabilities like CWE-843 to your infrastructure
EchelonGraph correlates every CVE — across CWE-843 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →