Vulnerabilities > Access of Resource Using Incompatible Type ('Type Confusion')

DATE CVE VULNERABILITY TITLE RISK
2022-04-05 CVE-2022-0795 Type Confusion vulnerability in Google Chrome
Type confusion in Blink Layout in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-843
8.8
2022-03-31 CVE-2022-1176 Type Confusion vulnerability in Livehelperchat Live Helper Chat
Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.
network
low complexity
livehelperchat CWE-843
5.0
2022-03-29 CVE-2021-46743 Type Confusion vulnerability in Google Firebase PHP-Jwt
In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring.
network
google CWE-843
5.8
2022-03-28 CVE-2021-26600 Type Confusion vulnerability in Impresscms
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).
network
low complexity
impresscms CWE-843
7.5
2022-03-18 CVE-2022-22661 Type Confusion vulnerability in Apple mac OS X and Macos
A type confusion issue was addressed with improved state handling.
local
low complexity
apple CWE-843
7.8
2022-03-10 CVE-2021-40061 Type Confusion vulnerability in Huawei Emui, Harmonyos and Magic UI
There is a vulnerability of accessing resources using an incompatible type (type confusion) in the Bastet module.
network
low complexity
huawei CWE-843
5.0
2022-02-22 CVE-2022-21656 Type Confusion vulnerability in Envoyproxy Envoy
Envoy is an open source edge and service proxy, designed for cloud-native applications.
network
high complexity
envoyproxy CWE-843
5.9
2022-02-14 CVE-2021-46463 Type Confusion vulnerability in F5 NJS
njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_then().
network
low complexity
f5 CWE-843
7.5
2022-02-12 CVE-2022-0102 Type Confusion vulnerability in multiple products
Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject CWE-843
8.8
2022-02-09 CVE-2021-46152 Type Confusion vulnerability in Siemens Simcenter Femap 2020.2/2021.1
A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions).
network
siemens CWE-843
6.8