CWE-843— Access of Resource Using Incompatible Type (Type Confusion)
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.— MITRE CWE catalog
973 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-843page 1 of 20
- CVE-2025-10585CRITICALCVSS 9.8EG 9.8⚠ KEV2025-09-24
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2012-0507CRITICALCVSS 9.8EG 9.8⚠ KEV2012-06-07
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and av…
- CVE-2024-7971CRITICALCVSS 9.6EG 9.6⚠ KEV2024-08-21
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-5274CRITICALCVSS 9.6EG 9.6⚠ KEV2024-05-28
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-4947CRITICALCVSS 9.6EG 9.6⚠ KEV2024-05-15
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-85046CRITICALCVSS 8.8EG 9.0⚠ KEV2026-09-03
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-13223CRITICALCVSS 8.8EG 9.0⚠ KEV2025-11-17
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-23222CRITICALCVSS 8.8EG 9.0⚠ KEV2024-01-23
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13…
- CVE-2023-4762CRITICALCVSS 8.8EG 9.0⚠ KEV2023-09-05
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-32439CRITICALCVSS 8.8EG 9.0⚠ KEV2023-06-23
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbit…
- CVE-2023-3079CRITICALCVSS 8.8EG 9.0⚠ KEV2023-06-05
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-2033CRITICALCVSS 8.8EG 9.0⚠ KEV2023-04-14
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-23529CRITICALCVSS 8.8EG 9.0⚠ KEV2023-02-27
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitra…
- CVE-2022-42856CRITICALCVSS 8.8EG 9.0⚠ KEV2022-12-15
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrar…
- CVE-2022-4262CRITICALCVSS 8.8EG 9.0⚠ KEV2022-12-02
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-3723CRITICALCVSS 8.8EG 9.0⚠ KEV2022-11-01
Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-1364CRITICALCVSS 8.8EG 9.0⚠ KEV2022-07-26
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2022-1096CRITICALCVSS 8.8EG 9.0⚠ KEV2022-07-23
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-30563CRITICALCVSS 8.8EG 9.0⚠ KEV2021-08-03
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-30551CRITICALCVSS 8.8EG 9.0⚠ KEV2021-06-15
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-21224CRITICALCVSS 8.8EG 9.0⚠ KEV2021-04-26
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- CVE-2021-1789CRITICALCVSS 8.8EG 9.0⚠ KEV2021-04-02
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0…
- CVE-2020-16009CRITICALCVSS 8.8EG 9.0⚠ KEV2020-11-03
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-17026CRITICALCVSS 8.8EG 9.0⚠ KEV2020-03-02
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird <…
- CVE-2020-6418CRITICALCVSS 8.8EG 9.0⚠ KEV2020-02-27
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-8506CRITICALCVSS 8.8EG 9.0⚠ KEV2019-12-18
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may le…
- CVE-2019-11707CRITICALCVSS 8.8EG 9.0⚠ KEV2019-07-23
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects F…
- CVE-2017-5070CRITICALCVSS 8.8EG 9.0⚠ KEV2017-10-27
Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- CVE-2017-11292CRITICALCVSS 8.8EG 9.0⚠ KEV2017-10-22
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitati…
- CVE-2016-7201CRITICALCVSS 8.8EG 9.0⚠ KEV2016-11-10
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a d…
- CVE-2011-0611CRITICALCVSS 8.8EG 9.0⚠ KEV2011-04-13
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through …
- CVE-2025-6554CRITICALCVSS 8.1EG 9.0⚠ KEV2025-06-30
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
- CVE-2017-0037CRITICALCVSS 8.1EG 9.0⚠ KEV2017-02-26
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary …
- CVE-2026-21519CRITICALCVSS 7.8EG 9.0⚠ KEV2026-02-10
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- CVE-2022-41033CRITICALCVSS 7.8EG 9.0⚠ KEV2022-10-11
Windows COM+ Event System Service Elevation of Privilege Vulnerability
- CVE-2021-30869CRITICALCVSS 7.8EG 9.0⚠ KEV2021-08-24
A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-00…
- CVE-2020-27932CRITICALCVSS 7.8EG 9.0⚠ KEV2020-12-08
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPa…
- CVE-2017-8291CRITICALCVSS 7.8EG 9.0⚠ KEV2017-04-27
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in t…
- CVE-2025-30397CRITICALCVSS 7.5EG 9.0⚠ KEV2025-05-13
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
- CVE-2024-38178CRITICALCVSS 7.5EG 9.0⚠ KEV2024-08-13
Scripting Engine Memory Corruption Vulnerability
- CVE-2019-0752CRITICALCVSS 7.5EG 9.0⚠ KEV2019-04-09
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-07…
- CVE-2018-8298CRITICALCVSS 7.5EG 9.0⚠ KEV2018-07-11
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-82…
- CVE-2021-33970CRITICALCVSS 10.0EG 10.02023-04-19
Buffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate priveleges.
- CVE-2010-2299HIGHCVSS v2 10.0EG 10.02010-06-15
The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 does not properly handle CBF_SMBITMAP objects in a ViewHostMsg_ClipboardWriteObjectsAsync message, which might allow remote attackers t…
- CVE-2023-22579CRITICALCVSS 9.9EG 9.92023-02-16
Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
- CVE-2026-106446CRITICALCVSS 9.8EG 9.82026-10-06
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLit…
- CVE-2026-104846CRITICALCVSS 9.8EG 9.82026-10-02
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearin…
- CVE-2026-71644CRITICALCVSS 9.8EG 9.82026-09-11
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops pub…
- CVE-2026-16919CRITICALCVSS 9.8EG 9.82026-08-19
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied pointers.
- CVE-2026-71558CRITICALCVSS 9.8EG 9.82026-08-07
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer dese…
Map vulnerabilities like CWE-843 to your infrastructure
EchelonGraph correlates every CVE — across CWE-843 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →