Vulnerability index

Browse CVEs

831 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
Immer CRITICAL 9.8
CVE-2021-23436

This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used i…

Fix: 9.0.6+
Fix from $2,300 2021-09-01
Debian Linux HIGH 8.6
CVE-2021-23434

This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components us…

Fix: 0.11.6+
Fix from $1,950 2021-08-27
Chrome HIGH 8.8
CVE-2021-30598EPSS 7%

Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 92.0.4515.159+
Fix from $1,950 2021-08-26
Chrome HIGH 8.8
CVE-2021-30599EPSS 5%

Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 92.0.4515.159+
Fix from $1,950 2021-08-26
Safari HIGH 8.8
CVE-2021-31008

A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 15.1, tvOS 15.1, iOS 15 and iPadOS 15, macOS Monter…

Fix: 8.1 / 15.0+
Fix from $1,950 2021-08-24
Safari HIGH 7.8
CVE-2021-30954

A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and …

Fix: 8.3 / 12.1+
Fix from $1,950 2021-08-24
Ipados HIGH 7.8
CVE-2021-30869 KEV

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, S…

Fix: 11.2 / 12.5.5+
Fix from $1,950 2021-08-24
Ipados HIGH 7.8
CVE-2021-30859

A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Upda…

Fix: 10.15.7 / 11.6+
Fix from $1,950 2021-08-24
Ipados HIGH 8.8
CVE-2021-30852

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, watchOS 8, iOS 15 and i…

Fix: 8.0 / 12.0.1+
Fix from $1,950 2021-08-24
Model HIGH 8.1
CVE-2020-36460

An issue was discovered in the model crate through 2020-11-10 for Rust. The Shared data structure has an implementation of the Send and Sync traits w…

Fix: after 2020-11-10
Fix from $1,950 2021-08-08
Chrome HIGH 8.8
CVE-2021-30588

Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 92.0.4515.107+
Fix from $1,950 2021-08-03
Chrome HIGH 8.8
CVE-2021-30561

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 91.0.4472.164+
Fix from $1,950 2021-08-03
Chrome HIGH 8.8
CVE-2021-30563 KEVEPSS 9%

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 91.0.4472.164+
Fix from $1,950 2021-08-03
Moddable HIGH 7.5
CVE-2020-22882

Issue was discovered in the fxParserTree function in moddable, allows attackers to cause denial of service via a crafted payload. Fixed in commit 723…

No fix yet
Fix from $1,950 2021-07-13
Design Review HIGH 7.8
CVE-2021-27038

A Type Confusion vulnerability in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can occur when processing a maliciously crafted PDF file. A mal…

Patch available
Fix from $1,950 2021-07-09
Emui CRITICAL 9.1
CVE-2021-22354

There is an Information Disclosure Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause out-of-bounds read.

No fix yet
Fix from $2,300 2021-06-30
Striptags MEDIUM 5.3
CVE-2021-32696

The npm package "striptags" is an implementation of PHP's strip_tags in Typescript. In striptags before version 3.2.0, a type-confusion vulnerability…

Fix: 3.2.0+
Fix from $1,600 2021-06-18
Foxit Reader HIGH 7.8
CVE-2021-31476EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.3.37598. User interaction is …

Fix: after 10.1.3.37598
Fix from $1,950 2021-06-16
Chrome HIGH 8.8
CVE-2021-30551 KEVEPSS 65%

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 91.0.4472.101+
Fix from $1,950 2021-06-15
Brava\! HIGH 7.8
CVE-2021-31480

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction…

Mitigation only
Fix from $1,950 2021-06-15
Chrome HIGH 8.8
CVE-2021-30517

Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 90.0.4430.212+
Fix from $1,950 2021-06-04
Chrome HIGH 8.8
CVE-2021-30513

Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 90.0.4430.212+
Fix from $1,950 2021-06-04
Zephyr HIGH 7.5
CVE-2021-3320

Type Confusion in 802154 ACK Frames Handling. Zephyr versions >= v2.4.0 contain NULL Pointer Dereference (CWE-476). For more information, see https:/…

Fix: after 2.4.0
Fix from $1,950 2021-05-25
Telegram MEDIUM 5.5
CVE-2021-31317

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custo…

Fix: 7.1.0+
Fix from $1,600 2021-05-18
Telegram MEDIUM 5.5
CVE-2021-31318

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTCompLayerItem…

Fix: 7.1.0+
Fix from $1,600 2021-05-18
Tensorflow HIGH 7.8
CVE-2021-29513

TensorFlow is an end-to-end open source platform for machine learning. Calling TF operations with tensors of non-numeric types when the operations ex…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29519

TensorFlow is an end-to-end open source platform for machine learning. The API of `tf.raw_ops.SparseCross` allows combinations which would result in …

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Headunit Ntg6 Mercedes Benz User Experience CRITICAL 9.8
CVE-2021-23908

An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A type confusion issue affects M…

No fix yet
Fix from $2,300 2021-05-13
Phantompdf HIGH 7.8
CVE-2021-31461

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is requ…

Fix: after 10.1.3.37598
Fix from $1,950 2021-05-07
Chrome HIGH 8.8
CVE-2021-21230

Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 90.0.4430.93+
Fix from $1,950 2021-04-30