Vulnerability index

Browse CVEs

831 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
Chrome HIGH 8.8
CVE-2023-0473

Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a c…

Fix: 109.0.5414.119+
Fix from $1,950 2023-01-30
GitLab HIGH 7.5
CVE-2022-4205

In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.

Fix: 12.9.8 / 15.5.5+
Fix from $1,950 2023-01-27
Android HIGH 7.8
CVE-2022-20461

In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of bounds read due to type confusion. This could lea…

Mitigation only
Fix from $1,950 2023-01-26
Linux Kernel MEDIUM 5.5
CVE-2023-23455

atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-…

Fix: after 6.1.4
Fix from $1,600 2023-01-12
Linux Kernel MEDIUM 5.5
CVE-2023-23454

cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because…

Fix: after 6.1.4
Fix from $1,600 2023-01-12
Windows 10 1607 HIGH 7.8
CVE-2023-21675

Windows Kernel Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2023-01-10
Aqt1000 Firmware HIGH 7.8
CVE-2022-25721

Memory corruption in video driver due to type confusion error during video playback

Patch available
Fix from $1,950 2023-01-09
Safari HIGH 8.8
CVE-2022-42856 KEVEPSS 9%

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and …

Fix: 13.1 / 15.7.2+
Fix from $1,950 2022-12-15
macOS HIGH 7.8
CVE-2022-42841

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2. Pr…

Fix: 11.7.2 / 12.6.2+
Fix from $1,950 2022-12-15
Chrome HIGH 8.8
CVE-2022-4262 KEVEPSS 15%

Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 108.0.5359.94+
Fix from $1,950 2022-12-02
Chrome HIGH 8.8
CVE-2022-4174

Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 108.0.5359.71+
Fix from $1,950 2022-11-30
Chrome HIGH 8.8
CVE-2022-3889

Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 107.0.5304.106+
Fix from $1,950 2022-11-09
Chrome HIGH 8.8
CVE-2022-3723 KEVEPSS 8%

Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 107.0.5304.87+
Fix from $1,950 2022-11-01
Chrome HIGH 8.8
CVE-2022-3652

Type confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

Fix: 107.0.5304.62+
Fix from $1,950 2022-11-01
Safari HIGH 8.8
CVE-2022-42823

A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS…

Fix: 9.1 / 13.0+
Fix from $1,950 2022-11-01
Chrome HIGH 8.8
CVE-2022-3315

Type confusion in Blink in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

Fix: 106.0.5249.62+
Fix from $1,950 2022-11-01
macOS HIGH 7.8
CVE-2022-32915

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code with…

Fix: 12.6.3+
Fix from $1,950 2022-11-01
Openj9 MEDIUM 6.5
CVE-2022-3676

In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlin…

Fix: 0.35.0+
Fix from $1,600 2022-10-24
Windows 10 1507 HIGH 7.8
CVE-2022-41033 KEV

Windows COM+ Event System Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.19507 / 10.0.14393.5427+
Fix from $1,950 2022-10-11
Ipados HIGH 7.8
CVE-2022-32814

A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Mon…

Fix: 8.7 / 11.6.8+
Fix from $1,950 2022-09-23
Libiec61850 HIGH 7.5
CVE-2022-2971

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) accesses a resource using …

Fix: 1.5.0+
Fix from $1,950 2022-09-23
Windows 10 MEDIUM 6.0
CVE-2022-34709

Windows Defender Credential Guard Security Feature Bypass Vulnerability

No fix yet
Fix from $1,600 2022-08-09
Android MEDIUM 6.7
CVE-2022-26430

In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution pri…

Mitigation only
Fix from $1,600 2022-08-01
Android MEDIUM 6.7
CVE-2022-26433

In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution pri…

Mitigation only
Fix from $1,600 2022-08-01
Android MEDIUM 6.7
CVE-2022-26435

In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution pri…

Mitigation only
Fix from $1,600 2022-08-01
Chrome HIGH 8.8
CVE-2022-2295

Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 103.0.5060.114+
Fix from $1,950 2022-07-28
Chrome MEDIUM 6.5
CVE-2022-1869

Type Confusion in V8 in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 102.0.5005.61+
Fix from $1,600 2022-07-27
Chrome HIGH 8.8
CVE-2022-1364 KEVEPSS 14%

Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted…

Fix: 100.0.4896.127+
Fix from $1,950 2022-07-26
Chrome HIGH 8.8
CVE-2022-1486

Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to obtain potentially sensitive information from process memor…

Fix: 101.0.4951.41+
Fix from $1,950 2022-07-26
Chrome HIGH 8.8
CVE-2022-1232EPSS 17%

Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 100.0.4896.75+
Fix from $1,950 2022-07-25