Vulnerability index

Browse CVEs

827 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
Aqt1000 Firmware HIGH 7.8
CVE-2023-28575

The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a w…

Patch available
Fix from $1,950 2023-08-08
Linux Kernel MEDIUM 5.5
CVE-2023-4194

A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized acc…

Fix: after 6.4
Fix from $1,600 2023-08-07
Chrome HIGH 8.1
CVE-2023-4068EPSS 16%

Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chr…

Fix: 115.0.5790.170+
Fix from $1,950 2023-08-03
Chrome HIGH 8.8
CVE-2023-4069EPSS 25%

Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 115.0.5790.170+
Fix from $1,950 2023-08-03
Chrome HIGH 8.1
CVE-2023-4070

Type Confusion in V8 in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chr…

Fix: 115.0.5790.170+
Fix from $1,950 2023-08-03
Chrome HIGH 8.8
CVE-2022-4912

Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 105.0.5195.52+
Fix from $1,950 2023-07-29
Control Fpwin Pro HIGH 7.8
CVE-2023-28729

A type confusion vulnerability in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when open…

Fix: after 7.6.0.3
Fix from $1,950 2023-07-21
Fedora MEDIUM 5.3
CVE-2023-34967EPSS 61%

A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data str…

Fix: 4.16.11 / 4.17.10+
Fix from $1,600 2023-07-20
Pdf Reader HIGH 7.8
CVE-2023-32664

A type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. Specially crafted Javascript…

No fix yet
Fix from $1,950 2023-07-19
Edge Chromium HIGH 7.8
CVE-2023-36887

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 114.0.1823.82+
Fix from $1,950 2023-07-14
Coreruleset CRITICAL 9.8
CVE-2023-38199

coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might a…

Fix: after 3.3.4
Fix from $2,300 2023-07-13
Windows 10 1607 HIGH 7.8
CVE-2023-35356

Windows Kernel Elevation of Privilege Vulnerability

Fix: 10.0.14393.6085 / 10.0.17763.4645+
Fix from $1,950 2023-07-11
Windows 10 1507 HIGH 8.1
CVE-2023-35297

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

Fix: 10.0.10240.20048 / 10.0.14393.6085+
Fix from $1,950 2023-07-11
Tecnomatix HIGH 7.8
CVE-2023-37376

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions…

Fix: 2201.0008 / 2302.0002+
Fix from $1,950 2023-07-11
Zephyr HIGH 8.8
CVE-2023-2234

Union variant confusion allows any malicious BT controller to execute arbitrary code on the Zephyr host.

Fix: after 3.3.0
Fix from $1,950 2023-07-10
Emui CRITICAL 9.8
CVE-2022-48511

Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of this vulnerability may cause a…

Mitigation only
Fix from $2,300 2023-07-06
Android MEDIUM 6.7
CVE-2023-20768

In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileg…

Mitigation only
Fix from $1,600 2023-07-04
Chrome HIGH 8.8
CVE-2023-3420EPSS 56%

Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 114.0.5735.198+
Fix from $1,950 2023-06-26
Safari HIGH 8.8
CVE-2023-32439 KEVEPSS 24%

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS V…

Fix: 2.42.3 / 13.4.1+
Fix from $1,950 2023-06-23
Ipados HIGH 7.8
CVE-2023-27930

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.…

Fix: 9.5 / 13.4+
Fix from $1,950 2023-06-23
Linux Kernel MEDIUM 5.5
CVE-2023-3022

A flaw was found in the IPv6 module of the Linux kernel. The arg.result was not used consistently in fib6_rule_lookup, sometimes holding rt6_info and…

Fix: after 5.1
Fix from $1,600 2023-06-19
Chrome HIGH 8.8
CVE-2023-3216

Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 114.0.5735.133+
Fix from $1,950 2023-06-13
Chrome HIGH 8.8
CVE-2023-3079 KEVEPSS 32%

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 7.1.5 / 114.0.5735.110+
Fix from $1,950 2023-06-05
Firefox HIGH 8.8
CVE-2023-28162

While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploita…

Fix: 102.9 / 111.0+
Fix from $1,950 2023-06-02
Chrome HIGH 8.8
CVE-2023-2935EPSS 24%

Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 114.0.5735.90+
Fix from $1,950 2023-05-30
Chrome HIGH 8.8
CVE-2023-2936EPSS 23%

Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 114.0.5735.90+
Fix from $1,950 2023-05-30
Hermes CRITICAL 9.8
CVE-2023-23557

An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad could be used by a malicious at…

Fix: 2023-01-10+
Fix from $2,300 2023-05-18
Hermes CRITICAL 9.8
CVE-2023-25933

A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious attacker to execute a…

Patch available
Fix from $2,300 2023-05-18
Chrome HIGH 8.8
CVE-2023-2724EPSS 29%

Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 113.0.5672.126+
Fix from $1,950 2023-05-16
Iot Yocto MEDIUM 6.7
CVE-2023-20673

In vcu, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privilege…

Mitigation only
Fix from $1,600 2023-05-15