İçeriğe atla
Noroxi

CWE-843 · 823 kayıt

Access of Resource Using Incompatible Type ('Type Confusion')

Bu sınıftaki CVE’ler

833 kayıt

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    oracle · jre7 Haz 2012

  • Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99

    adobe · flash player13 Nis 2011

  • Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %97

    artifex · ghostscript26 Nis 2017

  • Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %84

    google · chrome26 Nis 2021

  • The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (mem

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %80

    microsoft · edge10 Kas 2016

  • Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %79

    google · chrome27 Şub 2020

  • Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreak

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %80

    microsoft · edge26 Şub 2017

  • A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scrip

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %82

    microsoft · internet explorer9 Nis 2019

  • Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %65

    google · chrome15 Haz 2021

  • A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engin

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %75

    microsoft · chakracore10 Tem 2018

  • Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %49

    google · chrome3 Eyl 2026

  • CVE-2019-17026
    79Bu hafta

    Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %46

    mozilla · firefox2 Mar 2020

  • CVE-2023-4762
    77Bu hafta

    Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %41

    google · chrome5 Eyl 2023

  • CVE-2023-2033
    77Bu hafta

    Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %41

    google · chrome14 Nis 2023

  • CVE-2019-11707
    76Bu hafta

    A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %38

    mozilla · firefox23 Tem 2019

  • CVE-2023-3079
    75Bu hafta

    Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %32

    google · chrome5 Haz 2023

  • CVE-2017-5070
    75Bu hafta

    Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote atta

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %32

    google · chrome27 Eki 2017

  • CVE-2024-7971
    74Bu hafta

    Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page.

    KritikCVSS 9,6KEVSilahlaştırılmışEPSS %21

    google · chrome21 Ağu 2024

  • CVE-2024-4947
    73Bu hafta

    Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a craf

    KritikCVSS 9,6KEVSilahlaştırılmışEPSS %15

    google · chrome15 May 2024

  • CVE-2024-38178
    72Bu hafta

    Scripting Engine Memory Corruption Vulnerability

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %41

    microsoft · windows 10 150713 Ağu 2024

  • CVE-2022-1096
    72Bu hafta

    Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted H

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %24

    google · chrome22 Tem 2022

  • CVE-2023-32439
    72Bu hafta

    A type confusion issue was addressed with improved checks.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %24

    apple · safari23 Haz 2023

  • CVE-2025-10585
    71Bu hafta

    Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %5

    google · chrome24 Eyl 2025

  • CVE-2019-8506
    70Bu hafta

    A type confusion issue was addressed with improved memory handling.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %16

    apple · icloud18 Ara 2019

  • CVE-2022-4262
    70Bu hafta

    Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %16

    google · chrome2 Ara 2022

Tüm zafiyet sınıfları