CWE-843— Access of Resource Using Incompatible Type (Type Confusion)
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.— MITRE CWE catalog
842 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-843page 8 of 17
- CVE-2022-32814HIGHCVSS 7.8EG 7.82022-09-23
A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-32915HIGHCVSS 7.8EG 7.82022-11-01
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2022-3315HIGHCVSS 8.8EG 8.82022-11-01
Type confusion in Blink in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
- CVE-2022-34221HIGHCVSS 7.8EG 7.82022-07-15
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitra…
- CVE-2022-34709MEDIUMCVSS 6.0EG 6.02022-08-09
Windows Defender Credential Guard Security Feature Bypass Vulnerability
- CVE-2022-34918HIGHCVSS 7.8EG 7.82022-07-04
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (…
- CVE-2022-3652HIGHCVSS 8.8EG 8.82022-11-01
Type confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-3676MEDIUMCVSS 6.5EG 6.52022-10-24
In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlining to access or modify memory via an incompatible type.
- CVE-2022-3723CRITICALCVSS 8.8EG 9.0⚠ KEV2022-11-01
Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-37377HIGHCVSS 7.8EG 7.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor 11.1.1.53537;. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or …
- CVE-2022-3889HIGHCVSS 8.8EG 8.82022-11-09
Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-3903MEDIUMCVSS 4.6EG 4.62022-11-14
An incorrect read request flaw was found in the Infrared Transceiver USB driver in the Linux kernel. This issue occurs when a user attaches a malicious USB device. A local user could use this flaw to starve the resources, causing denial of…
- CVE-2022-41033CRITICALCVSS 7.8EG 9.0⚠ KEV2022-10-11
Windows COM+ Event System Service Elevation of Privilege Vulnerability
- CVE-2022-4174HIGHCVSS 8.8EG 8.82022-11-30
Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-4205HIGHCVSS 6.3EG 7.52023-01-27
In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.
- CVE-2022-4262CRITICALCVSS 8.8EG 9.0⚠ KEV2022-12-02
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-42823HIGHCVSS 8.8EG 8.82022-11-01
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code…
- CVE-2022-42841HIGHCVSS 7.8EG 7.82022-12-15
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2. Processing a maliciously crafted package may lead to arbitrary code execution.
- CVE-2022-42856CRITICALCVSS 8.8EG 9.0⚠ KEV2022-12-15
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrar…
- CVE-2022-46706HIGHCVSS 7.8EG 7.82023-08-14
A type confusion issue was addressed with improved state handling. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to execute arbitrary code with kernel privil…
- CVE-2022-48511CRITICALCVSS 9.8EG 9.82023-07-06
Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of this vulnerability may cause audio features to perform abnormally.
- CVE-2022-4912HIGHCVSS 8.8EG 8.82023-07-29
Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-50590MEDIUMCVSS 5.3EG 5.32025-11-06
SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers …
- CVE-2023-0083MEDIUMCVSS 4.0EG 5.52023-03-10
The ArKUI framework subsystem within OpenHarmony-v3.1.5 and prior versions, OpenHarmony-v3.0.7 and prior versions has an Improper Input Validation vulnerability which local attackers can exploit this vulnerability to send malicious data…
- CVE-2023-0286HIGHCVSS 7.4EG 8.32023-02-08
There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of …
- CVE-2023-0473HIGHCVSS 8.8EG 8.82023-01-30
Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-0696HIGHCVSS 8.8EG 8.82023-02-07
Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-0702HIGHCVSS 8.8EG 8.82023-02-07
Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security…
- CVE-2023-0703HIGHCVSS 8.8EG 8.82023-02-07
Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity…
- CVE-2023-1075LOWCVSS 3.3EG 3.32023-03-27
A flaw was found in the Linux Kernel. The tls_is_tx_ready() incorrectly checks for list emptiness, potentially accessing a type confused entry to the list_head, leaking the last byte of the confused field that overlaps with rec->tx_ready.
- CVE-2023-1076MEDIUMCVSS 5.5EG 5.52023-03-27
A flaw was found in the Linux Kernel. The tun/tap sockets have their socket UID hardcoded to 0 due to a type confusion in their initialization function. While it will be often correct, as tuntap devices require CAP_NET_ADMIN, it may not al…
- CVE-2023-1077HIGHCVSS 7.0EG 7.82023-03-27
In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the…
- CVE-2023-1078HIGHCVSS 7.8EG 7.82023-03-27
A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the head of a list causing a type confusion. Local user can trigger this with rds_message_put(). Type con…
- CVE-2023-1214HIGHCVSS 8.8EG 8.82023-03-07
Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-1215HIGHCVSS 8.8EG 8.82023-03-07
Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-1235MEDIUMCVSS 6.3EG 6.32023-03-07
Type confusion in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted UI interaction. (Chromium security severity: Low)
- CVE-2023-2033CRITICALCVSS 8.8EG 9.0⚠ KEV2023-04-14
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-20616MEDIUMCVSS 6.7EG 6.72023-02-06
In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue …
- CVE-2023-20673MEDIUMCVSS 6.7EG 6.72023-05-15
In vcu, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519103; Issue I…
- CVE-2023-20747MEDIUMCVSS 4.4EG 4.42023-06-06
In vcu, there is a possible memory corruption due to type confusion. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519103; Issue ID: ALP…
- CVE-2023-20768MEDIUMCVSS 6.7EG 6.72023-07-04
In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue …
- CVE-2023-21056MEDIUMCVSS 6.7EG 6.72023-03-24
In lwis_slc_buffer_free of lwis_device_slc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploit…
- CVE-2023-21287CRITICALCVSS 9.8EG 9.82023-08-14
In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-21675HIGHCVSS 7.8EG 7.82023-01-10
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-2234MEDIUMCVSS 6.8EG 6.82023-07-10
Union variant confusion allows any malicious BT controller to execute arbitrary code on the Zephyr host.
- CVE-2023-22579CRITICALCVSS 9.9EG 9.92023-02-16
Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
- CVE-2023-23442MEDIUMCVSS 4.6EG 4.62023-12-29
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
- CVE-2023-23443MEDIUMCVSS 4.6EG 4.62023-12-29
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
- CVE-2023-23454MEDIUMCVSS 5.5EG 5.52023-01-12
cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition ra…
- CVE-2023-23455MEDIUMCVSS 5.5EG 5.52023-01-12
atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classifi…
Map vulnerabilities like CWE-843 to your infrastructure
EchelonGraph correlates every CVE — across CWE-843 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →