CWE-843— Access of Resource Using Incompatible Type (Type Confusion)
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.— MITRE CWE catalog
842 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-843page 9 of 17
- CVE-2023-23529CRITICALCVSS 8.8EG 9.0⚠ KEV2023-02-27
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitra…
- CVE-2023-23557CRITICALCVSS 9.8EG 9.82023-05-18
An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad could be used by a malicious attacker to execute arbitrary code via type confusion. Note that this is only exploitable in…
- CVE-2023-24599MEDIUMCVSS 4.3EG 4.32023-05-29
OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion."
- CVE-2023-24823CRITICALCVSS 9.8EG 9.82023-04-24
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a type co…
- CVE-2023-24885HIGHCVSS 8.8EG 8.82023-04-11
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-24927HIGHCVSS 8.8EG 8.82023-04-11
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-24929HIGHCVSS 8.8EG 8.82023-04-11
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-24944MEDIUMCVSS 6.5EG 6.52023-05-09
Windows Bluetooth Driver Information Disclosure Vulnerability
- CVE-2023-25933CRITICALCVSS 9.8EG 9.82023-05-18
A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious attacker to execute arbitrary code via untrusted JavaScript. Note that this is only exploitable in cases where …
- CVE-2023-26063CRITICALCVSS 9.8EG 9.82023-04-10
Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.
- CVE-2023-2724HIGHCVSS 8.8EG 8.82023-05-16
Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-27930HIGHCVSS 7.8EG 7.82023-06-23
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2023-28162HIGHCVSS 8.8EG 8.82023-06-02
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird …
- CVE-2023-28243HIGHCVSS 8.8EG 8.82023-04-11
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-28575MEDIUMCVSS 6.7EG 6.72023-08-08
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
- CVE-2023-28729HIGHCVSS 7.8EG 7.82023-07-21
A type confusion vulnerability in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files.
- CVE-2023-2935HIGHCVSS 8.8EG 8.82023-05-30
Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-2936HIGHCVSS 8.8EG 8.82023-05-30
Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-3022MEDIUMCVSS 5.5EG 5.52023-06-19
A flaw was found in the IPv6 module of the Linux kernel. The arg.result was not used consistently in fib6_rule_lookup, sometimes holding rt6_info and other times fib6_info. This was not accounted for in other parts of the code where rt6_in…
- CVE-2023-3079CRITICALCVSS 8.8EG 9.0⚠ KEV2023-06-05
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-31322HIGHCVSS 8.7EG 8.72025-09-06
Type confusion in the ASP could allow an attacker to pass a malformed argument to the Reliability, Availability, and Serviceability trusted application (RAS TA) potentially leading to a read or write to shared memory resulting in loss of c…
- CVE-2023-31323HIGHCVSS 8.4EG 8.42026-02-12
Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety violation potentially resulting in loss of …
- CVE-2023-3216HIGHCVSS 8.8EG 8.82023-06-13
Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-32358HIGHCVSS 8.8EG 8.82023-08-14
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.
- CVE-2023-32439CRITICALCVSS 8.8EG 9.0⚠ KEV2023-06-23
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbit…
- CVE-2023-32664HIGHCVSS 8.8EG 8.82023-07-19
A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. Specially crafted Javascript code inside a malicious PDF document can cause memory corruption and lead to remote code …
- CVE-2023-32818MEDIUMCVSS 6.7EG 6.72023-11-06
In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896 & ALP…
- CVE-2023-32834MEDIUMCVSS 6.7EG 6.72023-11-06
In secmem, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08161762; Issu…
- CVE-2023-32835MEDIUMCVSS 6.7EG 6.72023-11-06
In keyinstall, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08157918; …
- CVE-2023-3420HIGHCVSS 8.8EG 8.92023-06-26
Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-34967HIGHCVSS 5.3EG 7.42023-07-20
A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the value…
- CVE-2023-35297HIGHCVSS 8.1EG 8.12023-07-11
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- CVE-2023-35356HIGHCVSS 7.8EG 7.82023-07-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-36017HIGHCVSS 8.8EG 8.82023-11-14
Windows Scripting Engine Memory Corruption Vulnerability
- CVE-2023-36578HIGHCVSS 7.3EG 7.32023-10-10
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36594HIGHCVSS 7.8EG 7.82023-10-10
Windows Graphics Component Elevation of Privilege Vulnerability
- CVE-2023-36887HIGHCVSS 7.8EG 7.82023-07-14
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2023-37376HIGHCVSS 7.8EG 7.82023-07-11
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application contains a type confusion vulnerability while par…
- CVE-2023-38073HIGHCVSS 7.8EG 7.82023-09-12
A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11),…
- CVE-2023-38074HIGHCVSS 7.8EG 7.82023-09-12
A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11),…
- CVE-2023-38091HIGHCVSS 7.8EG 7.82024-05-03
Kofax Power PDF response Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vu…
- CVE-2023-38128HIGHCVSS 7.8EG 7.82023-10-19
An out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause a type confusion, which can lead to memory corruption and eventually arbitrary code exec…
- CVE-2023-38199CRITICALCVSS 9.8EG 9.82023-07-13
coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might allow attackers to bypass a WAF with a crafted payload, aka "Content-Type confusion" betwee…
- CVE-2023-4068HIGHCVSS 8.1EG 8.12023-08-03
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-4069HIGHCVSS 8.8EG 8.82023-08-03
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-4070HIGHCVSS 8.1EG 8.12023-08-03
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-41060HIGHCVSS 8.8EG 8.82024-01-10
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. A remote user may be able to cause kernel code execution.
- CVE-2023-41075HIGHCVSS 7.8EG 7.82024-01-10
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4. An app may be able to execute arbitr…
- CVE-2023-41257HIGHCVSS 8.8EG 8.82023-11-27
A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corrup…
- CVE-2023-4194MEDIUMCVSS 5.5EG 5.52023-08-07
A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomple…
Map vulnerabilities like CWE-843 to your infrastructure
EchelonGraph correlates every CVE — across CWE-843 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →