CWE-843
904 CVEs • Abstraction: Base
Access of Resource Using Incompatible Type ('Type Confusion')
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
CVEs (904)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreAug 10, 2026 Feb 13, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....Show more |
In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation....Show more |
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14....Show more |
Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4. An app may be abl...Show more |
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. A remote user may be able to cause kernel code execution. |
1Microsoft 6Windows Server 2008 Windows Server 2012Windows Server 2016+3 moreJun 17, 2026 Jan 9, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability |
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause denial of service. |
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
|
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
|
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
|
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
|
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
|
3Fedoraproject GoogleMicrosoft3Chrome Edge ChromiumFedoraJun 17, 2026 Dec 14, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference and type confusi...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Nov 29, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security...Show more |
A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can le...Show more |
in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through type confusion. |
in OpenHarmony v3.2.2 and prior versions allow a local attacker causes system information leak through type confusion. |