Skip to main content

CWE archive

CWE-843 CVEs

Programmatic archive

851 CVEs tagged with CWE-843106 Critical, 561 High, 158 Medium, 26 Low, 0 Unrated.

CVE-2021-24045

Published Dec 13, 2021

A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0. Note that this is only exploitable if the applica…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-23820

Published Nov 3, 2021

This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23807

Published Nov 3, 2021

This affects the package jsonpointer before 5.0.0. A type confusion vulnerability can lead to a bypass of a previous Prototype Pollution fix when the pointer components are arrays.

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23624

Published Nov 3, 2021

This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are array…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23509

Published Nov 3, 2021

This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23472

Published Nov 3, 2021

This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of input sanitization when the input provided to the escapeHTML…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-6122

Published Nov 2, 2021

Type confusion in WebAssembly in Google Chrome prior to 66.0.3359.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-30627

Published Oct 8, 2021

Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-23447

Published Oct 7, 2021

This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23444

Published Sep 21, 2021

This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arr…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23443

Published Sep 21, 2021

This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization when the input to be rendered is an array (instead of a stri…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1829

Published Sep 8, 2021

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel priv…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 551-575 of 851 CVEsPage 23 of 35