CWE-843 · 823 kayıt
Access of Resource Using Incompatible Type ('Type Confusion')
Bu sınıftaki CVE’ler
833 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2012-0507Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,oracle · jre · CWE-843 | Kritik9,8 | KEV | %98,1 | 7 Haz 2012 |
95Hemen | CVE-2011-0611Silahlaştırılmış | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.adobe · flash player · CWE-843 | Yüksek8,8 | KEV | %99,4 | 13 Nis 2011 |
90Hemen | CVE-2017-8291Silahlaştırılmış | Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile artifex · ghostscript · CWE-843 | Yüksek7,8 | KEV | %97,0 | 26 Nis 2017 |
90Hemen | CVE-2021-21224Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craftgoogle · chrome · CWE-843 | Yüksek8,8 | KEV | %84,2 | 26 Nis 2021 |
89Hemen | CVE-2016-7201Silahlaştırılmış | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memmicrosoft · edge · CWE-843 | Yüksek8,8 | KEV | %80,0 | 10 Kas 2016 |
89Hemen | CVE-2020-6418Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted google · chrome · CWE-843 | Yüksek8,8 | KEV | %78,8 | 27 Şub 2020 |
86Hemen | CVE-2017-0037Silahlaştırılmış | Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakmicrosoft · edge · CWE-843 | Yüksek8,1 | KEV | %80,4 | 26 Şub 2017 |
84Hemen | CVE-2019-0752Silahlaştırılmış | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripmicrosoft · internet explorer · CWE-843 | Yüksek7,5 | KEV | %81,6 | 9 Nis 2019 |
84Hemen | CVE-2021-30551Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted google · chrome · CWE-843 | Yüksek8,8 | KEV | %64,7 | 15 Haz 2021 |
82Hemen | CVE-2018-8298Silahlaştırılmış | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Enginmicrosoft · chakracore · CWE-843 | Yüksek7,5 | KEV | %74,5 | 10 Tem 2018 |
80Hemen | CVE-2026-85046Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crgoogle · chrome · CWE-843 | Yüksek8,8 | KEV | %48,9 | 3 Eyl 2026 |
79Bu hafta | CVE-2019-17026Silahlaştırılmış | Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.mozilla · firefox · CWE-843 | Yüksek8,8 | KEV | %46,3 | 2 Mar 2020 |
77Bu hafta | CVE-2023-4762Silahlaştırılmış | Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page.google · chrome · CWE-843 | Yüksek8,8 | KEV | %41,4 | 5 Eyl 2023 |
77Bu hafta | CVE-2023-2033Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | Yüksek8,8 | KEV | %40,8 | 14 Nis 2023 |
76Bu hafta | CVE-2019-11707Silahlaştırılmış | A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.mozilla · firefox · CWE-843 | Yüksek8,8 | KEV | %37,7 | 23 Tem 2019 |
75Bu hafta | CVE-2023-3079Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | Yüksek8,8 | KEV | %32,1 | 5 Haz 2023 |
75Bu hafta | CVE-2017-5070Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attagoogle · chrome · CWE-843 | Yüksek8,8 | KEV | %32,1 | 27 Eki 2017 |
74Bu hafta | CVE-2024-7971Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page.google · chrome · CWE-843 | Kritik9,6 | KEV | %21,1 | 21 Ağu 2024 |
73Bu hafta | CVE-2024-4947Silahlaştırılmış | Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafgoogle · chrome · CWE-843 | Kritik9,6 | KEV | %15,2 | 15 May 2024 |
72Bu hafta | CVE-2024-38178Silahlaştırılmış | Scripting Engine Memory Corruption Vulnerabilitymicrosoft · windows 10 1507 · CWE-843 | Yüksek7,5 | KEV | %41,4 | 13 Ağu 2024 |
72Bu hafta | CVE-2022-1096Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted Hgoogle · chrome · CWE-843 | Yüksek8,8 | KEV | %24,2 | 22 Tem 2022 |
72Bu hafta | CVE-2023-32439Silahlaştırılmış | A type confusion issue was addressed with improved checks.apple · safari · CWE-843 | Yüksek8,8 | KEV | %24,0 | 23 Haz 2023 |
71Bu hafta | CVE-2025-10585Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | Kritik9,8 | KEV | %5,4 | 24 Eyl 2025 |
70Bu hafta | CVE-2019-8506Silahlaştırılmış | A type confusion issue was addressed with improved memory handling.apple · icloud · CWE-843 | Yüksek8,8 | KEV | %16,2 | 18 Ara 2019 |
70Bu hafta | CVE-2022-4262Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted google · chrome · CWE-843 | Yüksek8,8 | KEV | %16,0 | 2 Ara 2022 |
- CVE-2012-050798Hemen
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98oracle · jre7 Haz 2012
- CVE-2011-061195Hemen
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99adobe · flash player13 Nis 2011
- CVE-2017-829190Hemen
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %97artifex · ghostscript26 Nis 2017
- CVE-2021-2122490Hemen
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %84google · chrome26 Nis 2021
- CVE-2016-720189Hemen
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (mem
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %80microsoft · edge10 Kas 2016
- CVE-2020-641889Hemen
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %79google · chrome27 Şub 2020
- CVE-2017-003786Hemen
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreak
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %80microsoft · edge26 Şub 2017
- CVE-2019-075284Hemen
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %82microsoft · internet explorer9 Nis 2019
- CVE-2021-3055184Hemen
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %65google · chrome15 Haz 2021
- CVE-2018-829882Hemen
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engin
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %75microsoft · chakracore10 Tem 2018
- CVE-2026-8504680Hemen
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %49google · chrome3 Eyl 2026
- CVE-2019-1702679Bu hafta
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %46mozilla · firefox2 Mar 2020
- CVE-2023-476277Bu hafta
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %41google · chrome5 Eyl 2023
- CVE-2023-203377Bu hafta
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %41google · chrome14 Nis 2023
- CVE-2019-1170776Bu hafta
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %38mozilla · firefox23 Tem 2019
- CVE-2023-307975Bu hafta
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %32google · chrome5 Haz 2023
- CVE-2017-507075Bu hafta
Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote atta
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %32google · chrome27 Eki 2017
- CVE-2024-797174Bu hafta
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page.
KritikCVSS 9,6KEVSilahlaştırılmışEPSS %21google · chrome21 Ağu 2024
- CVE-2024-494773Bu hafta
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a craf
KritikCVSS 9,6KEVSilahlaştırılmışEPSS %15google · chrome15 May 2024
- CVE-2024-3817872Bu hafta
Scripting Engine Memory Corruption Vulnerability
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %41microsoft · windows 10 150713 Ağu 2024
- CVE-2022-109672Bu hafta
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted H
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %24google · chrome22 Tem 2022
- CVE-2023-3243972Bu hafta
A type confusion issue was addressed with improved checks.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %24apple · safari23 Haz 2023
- CVE-2025-1058571Bu hafta
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %5google · chrome24 Eyl 2025
- CVE-2019-850670Bu hafta
A type confusion issue was addressed with improved memory handling.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %16apple · icloud18 Ara 2019
- CVE-2022-426270Bu hafta
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %16google · chrome2 Ara 2022