CWE-843: CWE-843

206
Total CVEs
26
Critical
152
High
8.1
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
12
2025
68
2024
52
2023
35
2022
13

Top Affected Vendors

1 Google 67
2 Microsoft 32
3 Apple 25
4 Fedoraproject 21
5 Debian 12
6 Ashlar 7
7 Linux 5
8 Foxit 5
9 Siemens 5
10 Huawei 5

All CWE-843 CVEs (206)

CVE-2024-53427
8.1

A stack-based buffer overflow vulnerability in jq's decNumberCopy function allows out-of-bounds writes when processing specially crafted JSON input co...

Feb 26, 2025
CVE-2024-34392
8.1

libxmljs, a Node.js binding for libxml2, has a type confusion vulnerability when parsing specially crafted XML with namespaces() on a grand-child node...

May 2, 2024
CVE-2024-34394
8.1

libxmljs2 has a type confusion vulnerability when parsing malicious XML with entity references, then calling the namespaces() function on specific nod...

May 2, 2024
CVE-2024-21357
8.1

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General M...

Feb 13, 2024
CVE-2023-4068
8.1

This is a type confusion vulnerability in Chrome's V8 JavaScript engine that allows attackers to perform arbitrary memory read/write operations. Attac...

Aug 3, 2023
CVE-2023-4070
8.1

This vulnerability is a type confusion flaw in Chrome's V8 JavaScript engine that allows attackers to perform arbitrary memory read/write operations. ...

Aug 3, 2023
CVE-2023-35297
8.1

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General M...

Jul 11, 2023
CVE-2020-36460
8.1

This vulnerability in the Rust model crate allows data races and memory corruption by incorrectly marking the Shared data structure as thread-safe (Se...

Aug 8, 2021
CVE-2025-58310
8.0

A permission control vulnerability in Huawei's distributed component allows unauthorized access to sensitive information. This affects Huawei products...

Nov 28, 2025
CVE-2025-24137
8.0

This CVE describes a type confusion vulnerability in Apple operating systems that could allow a remote attacker to cause application crashes or execut...

Jan 27, 2025
CVE-2025-22153
7.9

A type confusion bug in CPython 3.11-3.13.1 when using try/except* statements allows bypassing RestrictedPython's security restrictions. This affects ...

Jan 23, 2025
CVE-2026-21330
7.8

Adobe After Effects versions 25.6 and earlier contain a type confusion vulnerability that could allow arbitrary code execution when a user opens a mal...

Feb 10, 2026
CVE-2026-20860
7.8

This vulnerability is a type confusion flaw in Windows Ancillary Function Driver for WinSock that allows an authenticated attacker to escalate privile...

Jan 13, 2026
CVE-2025-66586
7.8

A memory corruption vulnerability in AzeoTech DAQFactory allows attackers to execute arbitrary code by tricking users into opening malicious .ctl file...

Dec 11, 2025
CVE-2025-53739
7.8

A type confusion vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on a victim's system by tricking them into opening...

Aug 12, 2025
CVE-2025-53726
7.8

This is a type confusion vulnerability in Windows Push Notifications that allows an authenticated attacker to escalate privileges on a local system. A...

Aug 12, 2025
CVE-2025-53724
7.8

This vulnerability is a type confusion flaw in Windows Push Notifications that allows an authenticated attacker to escalate privileges on a local syst...

Aug 12, 2025
CVE-2025-7230
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of INVT VT-Designer when users open malici...

Jul 21, 2025
CVE-2025-49702
7.8

A type confusion vulnerability in Microsoft Office allows attackers to execute arbitrary code on vulnerable systems by tricking users into opening mal...

Jul 8, 2025
CVE-2025-30375
7.8

A type confusion vulnerability in Microsoft Office Excel allows attackers to execute arbitrary code on vulnerable systems by tricking users into openi...

May 13, 2025
CVE-2025-29791
7.8

A type confusion vulnerability in Microsoft Office allows attackers to execute arbitrary code on vulnerable systems by tricking users into opening mal...

Apr 8, 2025
CVE-2025-24213
7.8

A type confusion vulnerability in Apple's WebKit browser engine could allow memory corruption when processing floating-point numbers. This affects use...

Mar 31, 2025
CVE-2025-2018
7.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious VS...

Mar 11, 2025
CVE-2025-2022
7.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious VS...

Mar 11, 2025
CVE-2025-2015
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VS files in Ashlar-Vellum Cobalt softwar...

Mar 11, 2025
CVE-2025-2016
7.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious VC...

Mar 11, 2025
CVE-2025-21326
7.8

This CVE describes a remote code execution vulnerability in Internet Explorer that allows attackers to execute arbitrary code on affected systems. Att...

Jan 14, 2025
CVE-2024-13047
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious CO files or visiting malicious web pages...

Dec 30, 2024
CVE-2024-13049
7.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious XE...

Dec 30, 2024
CVE-2024-11507
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of IrfanView when users open malicious DXF...

Nov 22, 2024
CVE-2018-9339
7.8

This vulnerability allows local privilege escalation on Android devices through type confusion in Parcel.java's writeTypedArrayList and readTypedArray...

Nov 19, 2024
CVE-2024-45112
7.8

This CVE describes a Type Confusion vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious PDF ...

Sep 13, 2024
CVE-2024-38209
7.8

This vulnerability in Microsoft Edge (Chromium-based) allows remote attackers to execute arbitrary code on affected systems by tricking users into vis...

Aug 22, 2024
CVE-2024-32919
7.8

This vulnerability is a type confusion flaw in Android's Low-Level Workload Isolation System (LWIS) that allows local privilege escalation without use...

Jun 13, 2024
CVE-2024-5271
7.8

Fuji Electric Monitouch V-SFT software contains a type confusion vulnerability that leads to out-of-bounds write, potentially allowing attackers to ex...

May 30, 2024
CVE-2024-32063
7.8

A type confusion vulnerability in Simcenter Femap allows attackers to execute arbitrary code by tricking the application into misinterpreting data typ...

May 14, 2024
CVE-2024-32057
7.8

A type confusion vulnerability in Simcenter Femap allows attackers to execute arbitrary code by tricking the application into misinterpreting data typ...

May 14, 2024
CVE-2023-51560
7.8

This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...

May 3, 2024
CVE-2023-42105
7.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious AR...

May 3, 2024
CVE-2023-42074
7.8

This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files or visit...

May 3, 2024
CVE-2023-38091
7.8

This vulnerability in Kofax Power PDF allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files or visiting...

May 3, 2024
CVE-2024-30357
7.8

This vulnerability in Foxit PDF Reader allows attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw exists ...

Apr 2, 2024
CVE-2024-21363
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft Message Queuing (MSMQ) by sending specially crafted ...

Feb 13, 2024
CVE-2023-41075
7.8

A type confusion vulnerability in Apple operating systems allows malicious applications to execute arbitrary code with kernel privileges. This affects...

Jan 10, 2024
CVE-2023-36594
7.8

This Windows Graphics Component vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting improper...

Oct 10, 2023
CVE-2023-38073
7.8

A type confusion vulnerability in Siemens JT2Go, Teamcenter Visualization, and Tecnomatix Plant Simulation allows remote code execution when parsing m...

Sep 12, 2023
CVE-2023-28729
7.8

A type confusion vulnerability in Panasonic Control FPWIN Pro allows arbitrary code execution when opening malicious project files. This affects all v...

Jul 21, 2023
CVE-2023-36887
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Microsoft Edge. Attackers can exploit t...

Jul 14, 2023
CVE-2023-35356
7.8

CVE-2023-35356 is a Windows kernel elevation of privilege vulnerability that allows authenticated attackers to execute arbitrary code with SYSTEM priv...

Jul 11, 2023
CVE-2023-27930
7.8

This CVE describes a type confusion vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileg...

Jun 23, 2023

About CWE-843 (CWE-843)

Our database tracks 206 CVEs classified as CWE-843, with 26 rated critical and 152 rated high severity. The average CVSS score for CWE-843 vulnerabilities is 8.1.

External reference: View CWE-843 on MITRE CWE →

Monitor CWE-843 Vulnerabilities

Get alerted when new CWE-843 CVEs affect your infrastructure.

Start Monitoring Free