Vulnerability index

Browse CVEs

831 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
HIGH 8.8 CVE-2022-1314 Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Chrome 100.0.4896.88+ Fix from $1,9502022-07-25 HIGH 8.8 CVE-2022-1096 KEVEPSS 24% Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Chrome 99.0.4844.84+ Fix from $1,9502022-07-23 HIGH 8.8 CVE-2022-1134 Type confusion in V8 in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Chrome 100.0.4896.60+ Fix from $1,9502022-07-23 HIGH 7.8 CVE-2022-34221EPSS 11% Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an Access of Reso… Acrobat Dc after 22.001.20142 Fix from $1,9502022-07-15 HIGH 7.8 CVE-2022-34918EPSS 5% An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by… Linux Kernel 4.14.316 / 4.19.284+ Fix from $1,9502022-07-04 HIGH 7.8 CVE-2022-1786 A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one… Linux Kernel 5.12+ Fix from $1,9502022-06-02 HIGH 7.8 CVE-2021-26635 In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target file due to the wrong use of… Ark Library 7.17+ Fix from $1,9502022-06-02 HIGH 7.8 CVE-2021-32965 Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code. Diascreen 1.1.0+ Fix from $1,9502022-05-24 MEDIUM 5.5 CVE-2022-29209 TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the macros that TensorFlow uses for wri… Tensorflow 2.6.4 / 2.7.2+ Fix from $1,6002022-05-21 HIGH 8.2 CVE-2022-29181 Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX … Nokogiri 1.13.6 / 13.1+ Fix from $1,9502022-05-20 HIGH 7.5 CVE-2022-30557 Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript exe… Pdf Editor 11.2.2+ Fix from $1,9502022-05-11 MEDIUM 5.3 CVE-2021-41041 In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered… Openj9 0.32.0+ Fix from $1,6002022-04-27 HIGH 8.8 CVE-2022-0457 Type confusion in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Chrome 98.0.4758.80+ Fix from $1,9502022-04-05 HIGH 8.8 CVE-2022-0795 Type confusion in Blink Layout in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted … Chrome 99.0.4844.51+ Fix from $1,9502022-04-05 HIGH 7.5 CVE-2022-1176 Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96. Live Helper Chat 3.96+ Fix from $1,9502022-03-31 CRITICAL 9.1 CVE-2021-46743 In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of k… Firebase Php Jwt 6.0.0+ Fix from $2,3002022-03-29 CRITICAL 9.8 CVE-2021-26600EPSS 6% ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==). Impresscms 1.4.3+ Fix from $2,3002022-03-28 HIGH 7.8 CVE-2022-22661 A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update … Mac Os X 10.15.7 / 11.6.5+ Fix from $1,9502022-03-18 HIGH 7.5 CVE-2021-40061 There is a vulnerability of accessing resources using an incompatible type (type confusion) in the Bastet module. Successful exploitation of this vul… Emui No fix yet Fix from $1,9502022-03-10 MEDIUM 5.9 CVE-2022-21656 Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the… Envoy 1.20.2+ Fix from $1,6002022-02-22 CRITICAL 9.8 CVE-2021-46463 njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_the… Njs after 0.7.1 Fix from $2,3002022-02-14 HIGH 8.8 CVE-2022-0102 Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Chrome 97.0.4692.71+ Fix from $1,9502022-02-12 HIGH 7.8 CVE-2021-46152 A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains … Simcenter Femap Mitigation only Fix from $1,9502022-02-09 MEDIUM 6.5 CVE-2022-23583 Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that any bina… Tensorflow after 2.6.2 Fix from $1,6002022-02-04 MEDIUM 6.5 CVE-2022-21734 Tensorflow is an Open Source Machine Learning Framework. The implementation of `MapStage` is vulnerable a `CHECK`-fail if the key tensor is not a sca… Tensorflow after 2.6.2 Fix from $1,6002022-02-03 MEDIUM 6.5 CVE-2022-21731 Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `ConcatV2` can be used to trigger a denial of serv… Tensorflow after 2.6.2 Fix from $1,6002022-02-03 HIGH 7.8 CVE-2021-34866 This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain th… Linux Kernel 5.10.62 / 5.13.14+ Fix from $1,9502022-01-25 CRITICAL 9.8 CVE-2021-24044 By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke ge… Hermes 0.10.0+ Fix from $2,3002022-01-15 MEDIUM 5.5 CVE-2021-44647 Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service. Fedora Patch available Fix from $1,6002022-01-11 MEDIUM 5.5 CVE-2021-40037 There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploit… Harmonyos 2.0+ Fix from $1,6002022-01-10