Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-843

MITRE ↗

CWE-843

108
CRITICAL
565
HIGH
162
MEDIUM
26
LOW
870 CVEs · Page 9/18
7.8
CVE-2024-13047

Ashlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remot

7.8
CVE-2024-13049

Ashlar-Vellum Cobalt XE File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remot

7.7
CVE-2024-2887

Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary cod

7.5
CVE-2024-40803

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14

7.5
CVE-2024-38178 KEV

Scripting Engine Memory Corruption Vulnerability

7.5
CVE-2024-6119

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may atte

7.5
CVE-2024-7652

An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially

7.5
CVE-2024-56522

An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a con

7.4
CVE-2024-32922

In gpu_pm_power_on_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a logic er

7.3
CVE-2024-26232

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

7.3
CVE-2024-49860

In the Linux kernel, the following vulnerability has been resolved: ACPI: sysfs: validate return type of _STR method O

6.7
CVE-2024-20010

In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of

6.7
CVE-2024-20012

In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of

6.7
CVE-2024-20106

In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.5
CVE-2023-50433

marshall in dhcp_packet.c in simple-dhcp-server through ec976d2 allows remote attackers to cause a denial of service by

6.5
CVE-2023-46842

Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that the

6.5
CVE-2024-5843

Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate

6.5
CVE-2024-38219

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

6.5
CVE-2024-43489

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

6.5
CVE-2024-43596

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

6.3
CVE-2024-38207

Microsoft Edge (HTML-based) Memory Corruption Vulnerability

5.5
CVE-2024-30034

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

5.5
CVE-2024-40788

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9,

5.5
CVE-2024-34742

In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to

5.5
CVE-2024-54524

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2. A malicious app may

4.9
CVE-2024-20662

Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability

4.3
CVE-2024-47804

If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#is

3.3
CVE-2024-21834

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

3.3
CVE-2024-30266

wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its develo

3.3
CVE-2024-31071

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

3.3
CVE-2024-36278

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

2.9
CVE-2023-49602

in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type confusion.

10.0
CVE-2021-33970

Buffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate priveleges.

9.9
CVE-2023-22579

Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.

9.8
CVE-2023-26063

Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.

9.8
CVE-2023-24823

RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc

9.8
CVE-2023-23557

An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad co

9.8
CVE-2023-25933

A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a ma

9.8
CVE-2022-48511

Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of t

9.8
CVE-2023-38199

coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on

9.8
CVE-2023-21287

In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code executio

9.8
CVE-2023-42464

A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When pa

9.8
CVE-2023-43154

In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during l

8.8
CVE-2023-0473

Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially ex

8.8
CVE-2023-0696

Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corru

8.8
CVE-2023-0702

Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user t

8.8
CVE-2023-0703

Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to eng

8.8
CVE-2023-23529 KEV

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3

8.8
CVE-2023-1214

Type confusion in V8 in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corru

8.8
CVE-2023-1215

Type confusion in CSS in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corr

Frequently Asked Questions

What is CWE-843?

CWE-843 (CWE-843) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-843?

There are 1,092 CVE records associated with CWE-843 in our database. Of these, 108 are critical severity, 565 are high severity, and 162 are medium severity.

How can I protect against CWE-843 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-843 using AI-powered security agents.

Detect CWE-843 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-843 vulnerabilities across your infrastructure.

Get Started