CWE-843 · 823 records
Access of Resource Using Incompatible Type ('Type Confusion')
CVEs in this class
833 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
98Now | CVE-2012-0507Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,oracle · jre · CWE-843 | Critical9.8 | KEV | 98.1% | Jun 7, 2012 |
95Now | CVE-2011-0611Weaponized | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.adobe · flash player · CWE-843 | High8.8 | KEV | 99.4% | Apr 13, 2011 |
90Now | CVE-2017-8291Weaponized | Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile artifex · ghostscript · CWE-843 | High7.8 | KEV | 97.0% | Apr 26, 2017 |
90Now | CVE-2021-21224Weaponized | Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craftgoogle · chrome · CWE-843 | High8.8 | KEV | 84.2% | Apr 26, 2021 |
89Now | CVE-2016-7201Weaponized | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memmicrosoft · edge · CWE-843 | High8.8 | KEV | 80.0% | Nov 10, 2016 |
89Now | CVE-2020-6418Weaponized | Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted google · chrome · CWE-843 | High8.8 | KEV | 78.8% | Feb 27, 2020 |
86Now | CVE-2017-0037Weaponized | Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakmicrosoft · edge · CWE-843 | High8.1 | KEV | 80.4% | Feb 26, 2017 |
84Now | CVE-2019-0752Weaponized | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripmicrosoft · internet explorer · CWE-843 | High7.5 | KEV | 81.6% | Apr 9, 2019 |
84Now | CVE-2021-30551Weaponized | Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted google · chrome · CWE-843 | High8.8 | KEV | 64.7% | Jun 15, 2021 |
82Now | CVE-2018-8298Weaponized | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Enginmicrosoft · chakracore · CWE-843 | High7.5 | KEV | 74.5% | Jul 10, 2018 |
80Now | CVE-2026-85046Weaponized | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crgoogle · chrome · CWE-843 | High8.8 | KEV | 48.9% | Sep 3, 2026 |
79This week | CVE-2019-17026Weaponized | Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.mozilla · firefox · CWE-843 | High8.8 | KEV | 46.3% | Mar 2, 2020 |
77This week | CVE-2023-4762Weaponized | Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page.google · chrome · CWE-843 | High8.8 | KEV | 41.4% | Sep 5, 2023 |
77This week | CVE-2023-2033Weaponized | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | High8.8 | KEV | 40.8% | Apr 14, 2023 |
76This week | CVE-2019-11707Weaponized | A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.mozilla · firefox · CWE-843 | High8.8 | KEV | 37.7% | Jul 23, 2019 |
75This week | CVE-2023-3079Weaponized | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | High8.8 | KEV | 32.1% | Jun 5, 2023 |
75This week | CVE-2017-5070Weaponized | Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attagoogle · chrome · CWE-843 | High8.8 | KEV | 32.1% | Oct 27, 2017 |
74This week | CVE-2024-7971Weaponized | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page.google · chrome · CWE-843 | Critical9.6 | KEV | 21.1% | Aug 21, 2024 |
73This week | CVE-2024-4947Weaponized | Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafgoogle · chrome · CWE-843 | Critical9.6 | KEV | 15.2% | May 15, 2024 |
72This week | CVE-2024-38178Weaponized | Scripting Engine Memory Corruption Vulnerabilitymicrosoft · windows 10 1507 · CWE-843 | High7.5 | KEV | 41.4% | Aug 13, 2024 |
72This week | CVE-2022-1096Weaponized | Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted Hgoogle · chrome · CWE-843 | High8.8 | KEV | 24.2% | Jul 22, 2022 |
72This week | CVE-2023-32439Weaponized | A type confusion issue was addressed with improved checks.apple · safari · CWE-843 | High8.8 | KEV | 24.0% | Jun 23, 2023 |
71This week | CVE-2025-10585Weaponized | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | Critical9.8 | KEV | 5.4% | Sep 24, 2025 |
70This week | CVE-2019-8506Weaponized | A type confusion issue was addressed with improved memory handling.apple · icloud · CWE-843 | High8.8 | KEV | 16.2% | Dec 18, 2019 |
70This week | CVE-2022-4262Weaponized | Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted google · chrome · CWE-843 | High8.8 | KEV | 16.0% | Dec 2, 2022 |
- CVE-2012-050798Now
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
CriticalCVSS 9.8KEVWeaponizedEPSS 98%oracle · jreJun 7, 2012
- CVE-2011-061195Now
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.
HighCVSS 8.8KEVWeaponizedEPSS 99%adobe · flash playerApr 13, 2011
- CVE-2017-829190Now
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile
HighCVSS 7.8KEVWeaponizedEPSS 97%artifex · ghostscriptApr 26, 2017
- CVE-2021-2122490Now
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft
HighCVSS 8.8KEVWeaponizedEPSS 84%google · chromeApr 26, 2021
- CVE-2016-720189Now
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (mem
HighCVSS 8.8KEVWeaponizedEPSS 80%microsoft · edgeNov 10, 2016
- CVE-2020-641889Now
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted
HighCVSS 8.8KEVWeaponizedEPSS 79%google · chromeFeb 27, 2020
- CVE-2017-003786Now
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreak
HighCVSS 8.1KEVWeaponizedEPSS 80%microsoft · edgeFeb 26, 2017
- CVE-2019-075284Now
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip
HighCVSS 7.5KEVWeaponizedEPSS 82%microsoft · internet explorerApr 9, 2019
- CVE-2021-3055184Now
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted
HighCVSS 8.8KEVWeaponizedEPSS 65%google · chromeJun 15, 2021
- CVE-2018-829882Now
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engin
HighCVSS 7.5KEVWeaponizedEPSS 75%microsoft · chakracoreJul 10, 2018
- CVE-2026-8504680Now
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr
HighCVSS 8.8KEVWeaponizedEPSS 49%google · chromeSep 3, 2026
- CVE-2019-1702679This week
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.
HighCVSS 8.8KEVWeaponizedEPSS 46%mozilla · firefoxMar 2, 2020
- CVE-2023-476277This week
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
HighCVSS 8.8KEVWeaponizedEPSS 41%google · chromeSep 5, 2023
- CVE-2023-203377This week
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted
HighCVSS 8.8KEVWeaponizedEPSS 41%google · chromeApr 14, 2023
- CVE-2019-1170776This week
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.
HighCVSS 8.8KEVWeaponizedEPSS 38%mozilla · firefoxJul 23, 2019
- CVE-2023-307975This week
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted
HighCVSS 8.8KEVWeaponizedEPSS 32%google · chromeJun 5, 2023
- CVE-2017-507075This week
Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote atta
HighCVSS 8.8KEVWeaponizedEPSS 32%google · chromeOct 27, 2017
- CVE-2024-797174This week
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page.
CriticalCVSS 9.6KEVWeaponizedEPSS 21%google · chromeAug 21, 2024
- CVE-2024-494773This week
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a craf
CriticalCVSS 9.6KEVWeaponizedEPSS 15%google · chromeMay 15, 2024
- CVE-2024-3817872This week
Scripting Engine Memory Corruption Vulnerability
HighCVSS 7.5KEVWeaponizedEPSS 41%microsoft · windows 10 1507Aug 13, 2024
- CVE-2022-109672This week
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted H
HighCVSS 8.8KEVWeaponizedEPSS 24%google · chromeJul 22, 2022
- CVE-2023-3243972This week
A type confusion issue was addressed with improved checks.
HighCVSS 8.8KEVWeaponizedEPSS 24%apple · safariJun 23, 2023
- CVE-2025-1058571This week
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted
CriticalCVSS 9.8KEVWeaponizedEPSS 5%google · chromeSep 24, 2025
- CVE-2019-850670This week
A type confusion issue was addressed with improved memory handling.
HighCVSS 8.8KEVWeaponizedEPSS 16%apple · icloudDec 18, 2019
- CVE-2022-426270This week
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted
HighCVSS 8.8KEVWeaponizedEPSS 16%google · chromeDec 2, 2022