CWE-843
904 CVEs • Abstraction: Base
Access of Resource Using Incompatible Type ('Type Confusion')
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
CVEs (904)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Google Redhat4Chrome Enterprise Linux DesktopEnterprise Linux Server+1 moreMay 13, 2026 Oct 27, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. |
2Adobe Redhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreApr 22, 2026 Oct 22, 2017 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and su...Show more |
AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617 uses incorrect character data types, which causes a stack-based buffer underflow and out-of-bounds write, leading to denial of service (app...Show more |
3Artifex DebianRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+5 moreApr 21, 2026 Apr 27, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program...Show more |
1Microsoft 2Edge Internet ExplorerApr 22, 2026 Feb 26, 2017 N/A· v4 8.1 HIGH· v3 7.6 HIGH· v2 Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to...Show more |
1Adobe 2Flash Player Flash Player Desktop RuntimeMay 13, 2026 Feb 15, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable type confusion vulnerability related to the MessageChannel class. Successful exploitation could lead to arbitrary code execution. |
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption...Show more |
1Adobe 2Flash Player Flash Player Desktop RuntimeMay 6, 2026 Oct 13, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion." |
1Adobe 2Flash Player Flash Player Desktop RuntimeMay 6, 2026 Jul 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion,"...Show more |
1Adobe 2Flash Player Flash Player Desktop RuntimeMay 6, 2026 Jul 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion,"...Show more |
1Adobe 2Flash Player Flash Player Desktop RuntimeMay 6, 2026 Jul 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion,"...Show more |
4Adobe OpensuseRedhat+1 more8Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+5 moreMay 6, 2026 Jun 16, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different...Show more |
1Adobe 5Air Desktop Runtime Air SdkAir Sdk & Compiler+2 moreMay 6, 2026 Apr 9, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code by overriding NetConnection object properties t...Show more |
1Adobe 5Air Desktop Runtime Air SdkAir Sdk & Compiler+2 moreMay 6, 2026 Feb 10, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler be...Show more |
core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly check renderer state upon a focus...Show more |
Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly store internationalization metadata, which allows remote attackers to bypass intended acce...Show more |
4Debian GoogleNodejs+1 more4Chrome Debian LinuxNode.js+1 moreApr 29, 2026 Jul 31, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion." |
4Debian OracleSun+1 more7Debian Linux JreJre+4 moreAug 14, 2026 Jun 7, 2012 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality...Show more |
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbit...Show more |
Google V8, as used in Google Chrome before 14.0.835.163, does not properly perform object sealing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that lev...Show more |