Vulnerability index

Browse CVEs

831 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
Chrome HIGH 8.8
CVE-2022-1314

Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 100.0.4896.88+
Fix from $1,950 2022-07-25
Chrome HIGH 8.8
CVE-2022-1096 KEVEPSS 24%

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 99.0.4844.84+
Fix from $1,950 2022-07-23
Chrome HIGH 8.8
CVE-2022-1134

Type confusion in V8 in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 100.0.4896.60+
Fix from $1,950 2022-07-23
Acrobat Dc HIGH 7.8
CVE-2022-34221EPSS 11%

Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an Access of Reso…

Fix: after 22.001.20142
Fix from $1,950 2022-07-15
Linux Kernel HIGH 7.8
CVE-2022-34918EPSS 5%

An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by…

Fix: 4.14.316 / 4.19.284+
Fix from $1,950 2022-07-04
Linux Kernel HIGH 7.8
CVE-2022-1786

A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one…

Fix: 5.12+
Fix from $1,950 2022-06-02
Ark Library HIGH 7.8
CVE-2021-26635

In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target file due to the wrong use of…

Fix: 7.17+
Fix from $1,950 2022-06-02
Diascreen HIGH 7.8
CVE-2021-32965

Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code.

Fix: 1.1.0+
Fix from $1,950 2022-05-24
Tensorflow MEDIUM 5.5
CVE-2022-29209

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the macros that TensorFlow uses for wri…

Fix: 2.6.4 / 2.7.2+
Fix from $1,600 2022-05-21
Nokogiri HIGH 8.2
CVE-2022-29181

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX …

Fix: 1.13.6 / 13.1+
Fix from $1,950 2022-05-20
Pdf Editor HIGH 7.5
CVE-2022-30557

Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript exe…

Fix: 11.2.2+
Fix from $1,950 2022-05-11
Openj9 MEDIUM 5.3
CVE-2021-41041

In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered…

Fix: 0.32.0+
Fix from $1,600 2022-04-27
Chrome HIGH 8.8
CVE-2022-0457

Type confusion in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 98.0.4758.80+
Fix from $1,950 2022-04-05
Chrome HIGH 8.8
CVE-2022-0795

Type confusion in Blink Layout in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 99.0.4844.51+
Fix from $1,950 2022-04-05
Live Helper Chat HIGH 7.5
CVE-2022-1176

Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.

Fix: 3.96+
Fix from $1,950 2022-03-31
Firebase Php Jwt CRITICAL 9.1
CVE-2021-46743

In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of k…

Fix: 6.0.0+
Fix from $2,300 2022-03-29
Impresscms CRITICAL 9.8
CVE-2021-26600EPSS 6%

ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).

Fix: 1.4.3+
Fix from $2,300 2022-03-28
Mac Os X HIGH 7.8
CVE-2022-22661

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update …

Fix: 10.15.7 / 11.6.5+
Fix from $1,950 2022-03-18
Emui HIGH 7.5
CVE-2021-40061

There is a vulnerability of accessing resources using an incompatible type (type confusion) in the Bastet module. Successful exploitation of this vul…

No fix yet
Fix from $1,950 2022-03-10
Envoy MEDIUM 5.9
CVE-2022-21656

Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the…

Fix: 1.20.2+
Fix from $1,600 2022-02-22
Njs CRITICAL 9.8
CVE-2021-46463

njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_the…

Fix: after 0.7.1
Fix from $2,300 2022-02-14
Chrome HIGH 8.8
CVE-2022-0102

Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 97.0.4692.71+
Fix from $1,950 2022-02-12
Simcenter Femap HIGH 7.8
CVE-2021-46152

A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains …

Mitigation only
Fix from $1,950 2022-02-09
Tensorflow MEDIUM 6.5
CVE-2022-23583

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that any bina…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-21734

Tensorflow is an Open Source Machine Learning Framework. The implementation of `MapStage` is vulnerable a `CHECK`-fail if the key tensor is not a sca…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21731

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ConcatV2` can be used to trigger a denial of serv…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Linux Kernel HIGH 7.8
CVE-2021-34866

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain th…

Fix: 5.10.62 / 5.13.14+
Fix from $1,950 2022-01-25
Hermes CRITICAL 9.8
CVE-2021-24044

By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke ge…

Fix: 0.10.0+
Fix from $2,300 2022-01-15
Fedora MEDIUM 5.5
CVE-2021-44647

Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.

Patch available
Fix from $1,600 2022-01-11
Harmonyos MEDIUM 5.5
CVE-2021-40037

There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploit…

Fix: 2.0+
Fix from $1,600 2022-01-10