Vulnerability index

Browse CVEs

831 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
Chrome HIGH 8.8
CVE-2021-21224 KEVEPSS 56%

Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML p…

Fix: 90.0.4430.85+
Fix from $1,950 2021-04-26
Raw Image Extension HIGH 7.8
CVE-2021-28468EPSS 6%

Raw Image Extension Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-04-13
Fedora HIGH 8.8
CVE-2021-1789 KEVEPSS 13%

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Secu…

Fix: 2.30.6 / 7.3+
Fix from $1,950 2021-04-02
Debian Linux CRITICAL 9.8
CVE-2020-35636

A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::re…

No fix yet
Fix from $2,300 2021-03-04
Firefox HIGH 8.8
CVE-2021-23954

Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a …

Fix: 78.7 / 85.0+
Fix from $1,950 2021-02-26
Cx One HIGH 7.8
CVE-2020-27257

This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a…

Fix: after 5.0.28
Fix from $1,950 2021-02-09
Debian Linux HIGH 7.5
CVE-2020-36229

A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in deni…

Fix: 2.4.57 / 10.14.6+
Fix from $1,950 2021-01-26
Drawings Software Development Kit HIGH 7.8
CVE-2021-25177

An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Confusion issue exists when rendering malformed .DXF and .DWG fil…

Fix: 10.4.1 / 13.1.0.1+
Fix from $1,950 2021-01-18
Jt2go HIGH 8.8
CVE-2020-26990

A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications l…

Fix: 13.1.0.1+
Fix from $1,950 2021-01-12
Jt2go HIGH 8.8
CVE-2020-26980

A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack …

Fix: 13.1.0+
Fix from $1,950 2021-01-12
Cncsoft B HIGH 7.8
CVE-2020-27293

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a type confusion issue while processing project files, which may allow an attacker to exec…

Fix: after 1.0.0.2
Fix from $1,950 2021-01-11
Chrome HIGH 8.8
CVE-2020-16015

Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 87.0.4280.66+
Fix from $1,950 2021-01-08
Easysoft HIGH 7.8
CVE-2020-6656

Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity…

Fix: 7.20+
Fix from $1,950 2021-01-07
Failure CRITICAL 9.8
CVE-2019-25010

An issue was discovered in the failure crate through 2019-11-13 for Rust. Type confusion can occur when __private_get_type_id__ is overridden.

Fix: after 0.1.5
Fix from $2,300 2020-12-31
Foxit Reader HIGH 8.8
CVE-2020-13547

A type confusion vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF do…

No fix yet
Fix from $1,950 2020-12-22
Command Centre HIGH 8.8
CVE-2020-16103

Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue af…

Fix: 8.10.1211 / 8.20.1166+
Fix from $1,950 2020-12-14
Icloud HIGH 7.8
CVE-2020-27932 KEVEPSS 10%

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.…

Fix: 5.3.9 / 6.2.9+
Fix from $1,950 2020-12-08
Enterprise Linux HIGH 8.8
CVE-2020-25661

A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID. …

Mitigation only
Fix from $1,950 2020-11-05
Chrome HIGH 8.8
CVE-2020-16009 KEVEPSS 49%

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 86.0.241 / 86.0.622.63+
Fix from $1,950 2020-11-03
Safari HIGH 8.8
CVE-2020-9948

A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 14.0. Processing maliciously crafted web content ma…

Fix: 14.0+
Fix from $1,950 2020-10-16
Chrome HIGH 8.8
CVE-2020-15965

Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a craft…

Fix: 85.0.4183.121+
Fix from $1,950 2020-09-21
Chrome HIGH 8.8
CVE-2020-6537

Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 84.0.4147.105+
Fix from $1,950 2020-09-21
Android MEDIUM 6.7
CVE-2020-0336

In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution …

Mitigation only
Fix from $1,600 2020-09-17
Failure CRITICAL 9.8
CVE-2020-25575

An issue was discovered in the failure crate through 0.1.5 for Rust. It may introduce "compatibility hazards" in some applications, and has a type co…

Fix: after 0.1.8
Fix from $2,300 2020-09-14
Hermes CRITICAL 9.8
CVE-2020-1911

A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes prior to co…

Fix: 0.4.3+
Fix from $2,300 2020-09-04
Rgb Rust CRITICAL 9.1
CVE-2020-25016

A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leading to (for example) dereferencing of arbitrary pointers or disclosure…

Fix: 0.8.20+
Fix from $2,300 2020-08-29
Phantompdf HIGH 7.8
CVE-2020-15638EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.2.29539. User interaction is r…

Fix: after 10.0.0.35798
Fix from $1,950 2020-08-20
Firefox HIGH 8.8
CVE-2020-15656

JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions…

Fix: 78.1 / 79.0+
Fix from $1,950 2020-08-10
Webaccess\/hmi Designer HIGH 7.8
CVE-2020-16229

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied …

Fix: after 2.1.9.31
Fix from $1,950 2020-08-06
Chrome HIGH 8.8
CVE-2020-6533

Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22