CWE-843— Access of Resource Using Incompatible Type (Type Confusion)
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.— MITRE CWE catalog
842 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-843page 13 of 17
- CVE-2025-1920HIGHCVSS 8.8EG 8.82025-03-10
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-20063LOWCVSS 3.3EG 3.32025-06-08
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.
- CVE-2025-2015HIGHCVSS 7.8EG 7.82025-03-11
Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required t…
- CVE-2025-2016HIGHCVSS 7.8EG 7.82025-03-11
Ashlar-Vellum Cobalt VC6 File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required …
- CVE-2025-2018HIGHCVSS 7.8EG 7.82025-03-11
Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required t…
- CVE-2025-2022HIGHCVSS 7.8EG 7.82025-03-11
Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required t…
- CVE-2025-21082LOWCVSS 3.3EG 3.32025-06-08
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.
- CVE-2025-21225MEDIUMCVSS 5.9EG 5.92025-01-14
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
- CVE-2025-21279MEDIUMCVSS 6.5EG 6.52025-02-06
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2025-21326HIGHCVSS 7.8EG 7.82025-01-14
Internet Explorer Remote Code Execution Vulnerability
- CVE-2025-21342HIGHCVSS 8.8EG 8.82025-02-06
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2025-2135HIGHCVSS 8.8EG 8.82025-03-10
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-21356HIGHCVSS 7.8EG 7.82025-01-14
Microsoft Office Visio Remote Code Execution Vulnerability
- CVE-2025-21408HIGHCVSS 8.8EG 8.82025-02-06
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2025-2197MEDIUMCVSS 4.3EG 4.32025-04-17
Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service availability.
- CVE-2025-22151LOWCVSS 3.7EG 3.72025-01-09
Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQ…
- CVE-2025-22153HIGHCVSS 7.9EG 7.92025-01-23
RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Via a type confusion bug in versions of the CPython interpreter starting in 3.11 and prior …
- CVE-2025-22435CRITICALCVSS 9.8EG 9.82025-09-02
In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…
- CVE-2025-24129HIGHCVSS 7.5EG 7.52025-01-27
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may cause …
- CVE-2025-24137HIGHCVSS 8.0EG 8.02025-01-27
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3. An attacker on the local network may corrupt proce…
- CVE-2025-24213HIGHCVSS 7.8EG 7.82025-03-31
This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A type confusion issue could lead to memory …
- CVE-2025-24271MEDIUMCVSS 5.4EG 6.22025-04-29
An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An unauthenticated use…
- CVE-2025-25000HIGHCVSS 8.8EG 8.82025-04-04
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2025-25277HIGHCVSS 7.0EG 7.02026-03-16
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios.
- CVE-2025-26496CRITICALCVSS 9.3EG 9.62025-08-22
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau Server, Tableau Deskto…
- CVE-2025-27536LOWCVSS 3.3EG 3.32025-08-11
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion.
- CVE-2025-29791HIGHCVSS 7.8EG 7.82025-04-08
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-29806MEDIUMCVSS 6.5EG 6.52025-03-23
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2025-29867HIGHCVSS 8.5EG 8.52026-02-04
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Hancom Inc. Hancom Office 2018, Hancom Inc. Hancom Office 2020, Hancom Inc. Hancom Office 2022, Hancom Inc. Hancom Office 2024 allows File Content Injection.Thi…
- CVE-2025-30310HIGHCVSS 7.8EG 7.82025-05-13
Dreamweaver Desktop versions 21.4 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …
- CVE-2025-30375HIGHCVSS 7.8EG 7.82025-05-13
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-30383HIGHCVSS 7.8EG 7.82025-05-13
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-30397CRITICALCVSS 7.5EG 9.0⚠ KEV2025-05-13
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
- CVE-2025-30445MEDIUMCVSS 6.5EG 6.52025-04-29
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local net…
- CVE-2025-31206MEDIUMCVSS 4.3EG 4.32025-05-12
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web c…
- CVE-2025-32352MEDIUMCVSS 4.8EG 4.82025-04-05
A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires movi…
- CVE-2025-32948HIGHCVSS 7.5EG 7.52025-04-15
The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send ActivityPub activities to PeerTube's "inbox" endpoint. By abusing…
- CVE-2025-41738HIGHCVSS 7.5EG 7.52025-12-01
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
- CVE-2025-43236LOWCVSS 3.3EG 3.32026-04-02
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker may be able to cause unexpected app termination.
- CVE-2025-43297MEDIUMCVSS 6.2EG 6.22025-09-15
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26. An app may be able to cause a denial-of-service.
- CVE-2025-43355MEDIUMCVSS 5.5EG 5.52025-09-15
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may …
- CVE-2025-43506HIGHCVSS 7.5EG 7.52025-12-12
A logic error was addressed with improved error handling. This issue is fixed in macOS Tahoe 26.1. iCloud Private Relay may not activate when more than one user is logged in at the same time.
- CVE-2025-43541MEDIUMCVSS 4.3EG 4.52025-12-17
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may …
- CVE-2025-47151CRITICALCVSS 9.8EG 9.82025-11-05
A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed …
- CVE-2025-47167HIGHCVSS 8.4EG 8.42025-06-10
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-48756LOWCVSS 2.9EG 2.92025-05-24
In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small number of bits (e.g., 5 bits) for group number.
- CVE-2025-48815HIGHCVSS 7.8EG 7.82025-07-08
Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-49702HIGHCVSS 7.8EG 7.82025-07-08
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-49713HIGHCVSS 8.8EG 8.82025-07-02
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2025-50155HIGHCVSS 7.8EG 7.82025-08-12
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-843 to your infrastructure
EchelonGraph correlates every CVE — across CWE-843 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →