In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Re
The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definit
Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive
Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive
Type Confusion in Bluetooth in Google Chrome on Windows prior to 150.0.7871.47 allowed an attacker on the local network
Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose in
Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i
An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140
Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged t
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through u
The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value bein
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, mac
Deserialization of untrusted data vulnerability in Samsung Open Source Escargot Java Script allows denial of service con
Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from bein
jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin
Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point
Type Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised t
BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested Ser
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose i
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26
Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#in
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152
JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, F
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in ver
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can se
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial st
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plu
Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect avai
A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such
In mutt before 2.3.2, the imap_auth_gss security level is mishandled.
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Son
Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromise
Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Clou
A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulner
Frequently Asked Questions
What is CWE-843?
CWE-843 (CWE-843) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-843?
There are 390 CVE records associated with CWE-843 in our database. Of these, 53 are critical severity, 229 are high severity, and 52 are medium severity.
How can I protect against CWE-843 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-843 using AI-powered security agents.
Detect CWE-843 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-843 vulnerabilities across your infrastructure.
Get Started