Vulnerabilities > Access of Resource Using Incompatible Type ('Type Confusion')

DATE CVE VULNERABILITY TITLE RISK
2023-09-27 CVE-2023-43154 Type Confusion vulnerability in Macs CMS Project Macs CMS 1.1.4F
In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.
network
low complexity
macs-cms-project CWE-843
critical
9.8
2023-09-20 CVE-2023-42464 Type Confusion vulnerability in multiple products
A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17.
network
low complexity
netatalk debian CWE-843
critical
9.8
2023-09-05 CVE-2023-4762 Type Confusion vulnerability in multiple products
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
network
low complexity
google debian fedoraproject microsoft CWE-843
8.8
2023-08-15 CVE-2023-4352 Type Confusion vulnerability in multiple products
Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google debian fedoraproject CWE-843
8.8
2023-08-14 CVE-2022-46706 Type Confusion vulnerability in Apple mac OS X and Macos
A type confusion issue was addressed with improved state handling.
local
low complexity
apple CWE-843
7.8
2023-08-14 CVE-2023-32358 Type Confusion vulnerability in Apple Ipados, Iphone OS and Macos
A type confusion issue was addressed with improved checks.
network
low complexity
apple CWE-843
8.8
2023-08-14 CVE-2023-21287 Type Confusion vulnerability in Google Android
In multiple locations, there is a possible code execution due to type confusion.
network
low complexity
google CWE-843
critical
9.8
2023-08-08 CVE-2023-28575 Type Confusion vulnerability in Qualcomm products
The cam_get_device_priv function does not check the type of handle being returned (device/session/link).
local
low complexity
qualcomm CWE-843
7.8
2023-08-03 CVE-2023-4068 Type Confusion vulnerability in Google Chrome
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page.
network
low complexity
google CWE-843
8.1
2023-08-03 CVE-2023-4069 Type Confusion vulnerability in Google Chrome
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-843
8.8