Vulnerabilities > Access of Resource Using Incompatible Type ('Type Confusion')

DATE CVE VULNERABILITY TITLE RISK
2023-08-08 CVE-2023-28575 Type Confusion vulnerability in Qualcomm products
The cam_get_device_priv function does not check the type of handle being returned (device/session/link).
local
low complexity
qualcomm CWE-843
7.8
2023-08-03 CVE-2023-4068 Type Confusion vulnerability in Google Chrome
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page.
network
low complexity
google CWE-843
8.1
2023-08-03 CVE-2023-4069 Type Confusion vulnerability in Google Chrome
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-843
8.8
2023-08-03 CVE-2023-4070 Type Confusion vulnerability in Google Chrome
Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page.
network
low complexity
google CWE-843
8.1
2023-07-29 CVE-2022-4912 Type Confusion vulnerability in Google Chrome
Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-843
8.8
2023-07-21 CVE-2023-28729 Type Confusion vulnerability in Panasonic Control Fpwin PRO 6.414/7.3.0.0
A type confusion vulnerability in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files.
local
low complexity
panasonic CWE-843
7.8
2023-07-20 CVE-2023-34967 Type Confusion vulnerability in multiple products
A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight.
network
low complexity
samba fedoraproject redhat debian CWE-843
5.3
2023-07-13 CVE-2023-38199 Type Confusion vulnerability in Owasp Coreruleset
coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms.
network
low complexity
owasp CWE-843
critical
9.8
2023-07-11 CVE-2023-37376 Type Confusion vulnerability in Siemens Tecnomatix 2201/2302
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002).
local
low complexity
siemens CWE-843
7.8
2023-07-10 CVE-2023-2234 Type Confusion vulnerability in Zephyrproject Zephyr
Union variant confusion allows any malicious BT controller to execute arbitrary code on the Zephyr host.
low complexity
zephyrproject CWE-843
8.8