Skip to main content

CWE archive

CWE-843 CVEs

Programmatic archive

837 CVEs tagged with CWE-843100 Critical, 554 High, 156 Medium, 26 Low, 1 Unrated.

CVE-2025-5959

Published Jun 11, 2025

Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security seve…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-21082

Published Jun 8, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-20063

Published Jun 8, 2025

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-48756

Published May 24, 2025

In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small number of bits (e.g., 5 bits) for group number.

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-58253

Published May 2, 2025

In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to invalid UTF-8 conversion that produces an invalid value.

CVSS 2.9 · Low

CVE-2025-2197

Published Apr 17, 2025

Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service availability.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32948

Published Apr 15, 2025

The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send Activi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32352

Published Apr 5, 2025

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes…

CVSS 4.8 · Medium

CVE-2025-25000

Published Apr 4, 2025

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-2022

Published Mar 11, 2025

Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-2018

Published Mar 11, 2025

Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-2016

Published Mar 11, 2025

Ashlar-Vellum Cobalt VC6 File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-2015

Published Mar 11, 2025

Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 226-250 of 837 CVEsPage 10 of 34