Skip to content
Noroxi

CWE-843 · 823 records

Access of Resource Using Incompatible Type ('Type Confusion')

CVEs in this class

833 records

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    oracle · jreJun 7, 2012

  • Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.

    HighCVSS 8.8KEVWeaponizedEPSS 99%

    adobe · flash playerApr 13, 2011

  • Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile

    HighCVSS 7.8KEVWeaponizedEPSS 97%

    artifex · ghostscriptApr 26, 2017

  • Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft

    HighCVSS 8.8KEVWeaponizedEPSS 84%

    google · chromeApr 26, 2021

  • The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (mem

    HighCVSS 8.8KEVWeaponizedEPSS 80%

    microsoft · edgeNov 10, 2016

  • Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted

    HighCVSS 8.8KEVWeaponizedEPSS 79%

    google · chromeFeb 27, 2020

  • Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreak

    HighCVSS 8.1KEVWeaponizedEPSS 80%

    microsoft · edgeFeb 26, 2017

  • A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip

    HighCVSS 7.5KEVWeaponizedEPSS 82%

    microsoft · internet explorerApr 9, 2019

  • Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted

    HighCVSS 8.8KEVWeaponizedEPSS 65%

    google · chromeJun 15, 2021

  • A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engin

    HighCVSS 7.5KEVWeaponizedEPSS 75%

    microsoft · chakracoreJul 10, 2018

  • Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr

    HighCVSS 8.8KEVWeaponizedEPSS 49%

    google · chromeSep 3, 2026

  • CVE-2019-17026
    79This week

    Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.

    HighCVSS 8.8KEVWeaponizedEPSS 46%

    mozilla · firefoxMar 2, 2020

  • CVE-2023-4762
    77This week

    Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

    HighCVSS 8.8KEVWeaponizedEPSS 41%

    google · chromeSep 5, 2023

  • CVE-2023-2033
    77This week

    Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted

    HighCVSS 8.8KEVWeaponizedEPSS 41%

    google · chromeApr 14, 2023

  • CVE-2019-11707
    76This week

    A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.

    HighCVSS 8.8KEVWeaponizedEPSS 38%

    mozilla · firefoxJul 23, 2019

  • CVE-2023-3079
    75This week

    Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted

    HighCVSS 8.8KEVWeaponizedEPSS 32%

    google · chromeJun 5, 2023

  • CVE-2017-5070
    75This week

    Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote atta

    HighCVSS 8.8KEVWeaponizedEPSS 32%

    google · chromeOct 27, 2017

  • CVE-2024-7971
    74This week

    Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page.

    CriticalCVSS 9.6KEVWeaponizedEPSS 21%

    google · chromeAug 21, 2024

  • CVE-2024-4947
    73This week

    Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a craf

    CriticalCVSS 9.6KEVWeaponizedEPSS 15%

    google · chromeMay 15, 2024

  • CVE-2024-38178
    72This week

    Scripting Engine Memory Corruption Vulnerability

    HighCVSS 7.5KEVWeaponizedEPSS 41%

    microsoft · windows 10 1507Aug 13, 2024

  • CVE-2022-1096
    72This week

    Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted H

    HighCVSS 8.8KEVWeaponizedEPSS 24%

    google · chromeJul 22, 2022

  • CVE-2023-32439
    72This week

    A type confusion issue was addressed with improved checks.

    HighCVSS 8.8KEVWeaponizedEPSS 24%

    apple · safariJun 23, 2023

  • CVE-2025-10585
    71This week

    Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted

    CriticalCVSS 9.8KEVWeaponizedEPSS 5%

    google · chromeSep 24, 2025

  • CVE-2019-8506
    70This week

    A type confusion issue was addressed with improved memory handling.

    HighCVSS 8.8KEVWeaponizedEPSS 16%

    apple · icloudDec 18, 2019

  • CVE-2022-4262
    70This week

    Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted

    HighCVSS 8.8KEVWeaponizedEPSS 16%

    google · chromeDec 2, 2022

All vulnerability classes