CWE-843
833 CVEs • Abstraction: Base
Access of Resource Using Incompatible Type ('Type Confusion')
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
CVEs (833)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays. |
This affects the package jsonpointer before 5.0.0. A type confusion vulnerability can lead to a bypass of a previous Prototype Pollution fix when the pointer components are arrays. |
This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays. |
This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays. |
1Bootstrap Table 1Bootstrap Table Jun 17, 2026 Nov 3, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML function is an array (instead of a strin...Show more |
Type confusion in WebAssembly in Google Chrome prior to 66.0.3359.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
1Apple 6Ipados Iphone OsMacos+3 moreJun 17, 2026 Oct 28, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, Safari 15, watchOS 8. Processing maliciously crafted web content may lead...Show more |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Oct 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string). |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreJun 17, 2026 Sep 29, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Type Confusion vulnerability. An attacker could leverage this vulnerability to exec...Show more |
This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function. |
This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization when the input to be rendered is an array (instead of a string or a SafeValue), even if {{ }} are use...Show more |
2Bytecodealliance Fedoraproject2Fedora WasmtimeJun 17, 2026 Sep 17, 2021 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 Wasmtime is an open source runtime for WebAssembly & WASI. Wasmtime before version 0.30.0 is affected by a type confusion vulnerability. As a Rust library the `wasmtime` crate clearly marks which functions are safe and w...Show more |
Microsoft Office Graphics Remote Code Execution Vulnerability |
2Oracle Set Value Project2Communications Cloud Native Core Policy Set ValueJun 17, 2026 Sep 12, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays. |
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel privileges. |
1Apple 5Iphone Os MacosSafari+2 moreJun 17, 2026 Sep 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitr...Show more |
This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__pro...Show more |
This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible...Show more |
2Debian Object Path Project2Debian Linux Object PathJun 17, 2026 Aug 27, 2021 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition curre...Show more |