CWE-843: CWE-843
Yearly Trend
Top Affected Vendors
All CWE-843 CVEs (201)
A JIT miscompilation vulnerability in Firefox's JavaScript: WebAssembly component could allow arbitrary code execution when processing malicious web c...
Feb 24, 2026A type confusion vulnerability in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an 'instanceof' expression uses...
Dec 29, 2025A type confusion vulnerability in Entr'ouvert Lasso's SAML parsing allows remote code execution when processing malicious SAML responses. This affects...
Nov 5, 2025A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the browser into misinterpreti...
Sep 24, 2025This vulnerability allows memory corruption via type confusion in Android's Bluetooth AVDT protocol implementation. An attacker with paired Bluetooth ...
Sep 2, 2025A type confusion vulnerability in Webroot SecureAnywhere's Web Shield component allows attackers to misuse functionality by accessing resources with i...
Oct 3, 2024This vulnerability allows attackers to trigger type confusion when accessing properties on objects used as 'with' statement environments in Mozilla pr...
Sep 3, 2024This is a critical type confusion vulnerability in MediaTek's venc component that allows local privilege escalation. Attackers can execute arbitrary c...
Jul 1, 2024This vulnerability allows attackers to bypass authentication in Macrob7 Macs Framework CMS 1.1.4f by exploiting PHP type confusion in the login valida...
Sep 27, 2023A Type Confusion vulnerability in Netatalk's afpd service allows remote attackers to potentially execute arbitrary code by sending malicious Spotlight...
Sep 20, 2023This CVE describes a type confusion vulnerability in Android's FreeType library that allows remote code execution without user interaction. Attackers ...
Aug 14, 2023A type confusion vulnerability in Hermes JavaScript engine's TypedArray implementation allows arbitrary code execution when processing untrusted JavaS...
May 18, 2023This vulnerability in Lexmark devices allows attackers to access resources using incompatible types, potentially leading to remote code execution or d...
Apr 10, 2023CVE-2021-46463 is a critical type confusion vulnerability in njs (NGINX JavaScript) that allows attackers to hijack control flow and potentially execu...
Feb 14, 2022This vulnerability in Hermes JavaScript engine allows attackers to cause type confusion by passing invalid JavaScript code with await/yield calls on n...
Jan 15, 2022A type confusion vulnerability in Facebook Hermes JavaScript engine prior to v0.10.0 could allow arbitrary code execution when processing untrusted Ja...
Dec 13, 2021CVE-2021-1829 is a type confusion vulnerability in macOS that allows an application to execute arbitrary code with kernel privileges. This affects mac...
Sep 8, 2021This vulnerability in the Rust failure crate (versions through 0.1.5) involves a type confusion flaw when downcasting, which could lead to memory corr...
Sep 14, 2020A type confusion vulnerability in Facebook's Hermes JavaScript engine allows attackers to potentially execute arbitrary code by crafting malicious Jav...
Sep 4, 2020This is a type confusion vulnerability in Chrome's V8 JavaScript engine that allows remote attackers to trigger heap corruption via malicious HTML pag...
Aug 21, 2024This is a type confusion vulnerability in Chrome's V8 JavaScript engine that allows remote attackers to execute arbitrary code within the browser's sa...
May 28, 2024This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that allows remote attackers to execute arbitrary code within the browser...
May 15, 2024A permission control vulnerability in the memory management module allows unauthorized access to sensitive memory regions. This affects confidentialit...
Nov 28, 2025This CVE describes a type confusion vulnerability in Salesforce Tableau's file upload modules that allows local attackers to include and execute arbit...
Aug 22, 2025This is a type confusion vulnerability in the xray-monolith software that allows attackers to access memory with incompatible types, potentially leadi...
Jan 27, 2026CVE-2021-46743 is an algorithm confusion vulnerability in Firebase PHP-JWT library that allows attackers to forge JWT tokens by exploiting key ID (kid...
Mar 29, 2022A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to corrupt heap memory via malicious web pages. This could lead to ar...
Feb 3, 2026A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...
Dec 2, 2025A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the browser into misinterpreti...
Nov 18, 2025A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...
Nov 18, 2025A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...
Nov 18, 2025A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...
Nov 18, 2025A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...
Nov 18, 2025This is a type confusion vulnerability in Chrome's V8 JavaScript engine that could allow an attacker to execute arbitrary code or cause heap corruptio...
Nov 17, 2025A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...
Nov 17, 2025A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to perform arbitrary memory read/write operations through a malicious...
Nov 10, 2025A type confusion vulnerability in Windows Message Queuing allows authenticated attackers to execute arbitrary code remotely. This affects systems with...
Aug 12, 2025A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption by tricking the engine into treating one d...
Jul 22, 2025This vulnerability allows remote attackers to execute arbitrary code within Chrome's sandbox through type confusion in the V8 JavaScript engine. Users...
Jun 11, 2025A type confusion vulnerability in Chrome's V8 JavaScript engine could allow attackers to execute arbitrary code or cause heap corruption by tricking u...
Mar 10, 2025This is a type confusion vulnerability in Chrome's V8 JavaScript engine that could allow an attacker to trigger heap corruption by tricking the browse...
Mar 10, 2025This vulnerability in Microsoft Edge (Chromium-based) allows remote attackers to execute arbitrary code on affected systems by tricking users into vis...
Feb 6, 2025This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Microsoft Edge. Attackers could exploit...
Feb 6, 2025A type confusion vulnerability in Zoom Workplace App for Linux allows authenticated users to escalate privileges through network access. This affects ...
Jan 30, 2025This is a type confusion vulnerability in Chrome's V8 JavaScript engine that allows remote attackers to execute arbitrary code within the browser's sa...
Jan 8, 2025This CVE describes a type confusion vulnerability in Apple's WebKit browser engine that could allow memory corruption when processing malicious web co...
Dec 12, 2024A type confusion vulnerability in Chrome's V8 JavaScript engine allows attackers to corrupt memory objects through malicious HTML pages. This could le...
Dec 3, 2024This is a type confusion vulnerability in Chrome's V8 JavaScript engine that allows attackers to trigger heap corruption through malicious web pages. ...
Nov 19, 2024This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that allows a remote attacker to trigger heap corruption by tricking the ...
Oct 22, 2024This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that allows attackers to write data outside intended memory bounds. Attac...
Oct 8, 2024About CWE-843 (CWE-843)
Our database tracks 201 CVEs classified as CWE-843, with 26 rated critical and 147 rated high severity. The average CVSS score for CWE-843 vulnerabilities is 8.1.
External reference: View CWE-843 on MITRE CWE →
Monitor CWE-843 Vulnerabilities
Get alerted when new CWE-843 CVEs affect your infrastructure.
Start Monitoring Free