Weaknesses of type CWE-843

686 results

Confusão de Tipos

Ocorre quando o programa trata uma variável ou objeto como se fosse de um tipo diferente do seu tipo real, levando a comportamentos impredizíveis. O atacante explora essa interpretação errada para contornar validações, corromper memória ou executar código arbitrário.

Example

Um aplicativo recebe um valor que valida como inteiro, mas a função que o processa o interpreta como um ponteiro de memória. O código tenta acessar e modificar dados no endereço apontado, causando corrupção ou exposição de informações sensíveis.

How to mitigate

Implemente validação rigorosa e conversão explícita de tipos antes de usar qualquer dado externo. Use linguagens com verificação forte de tipos em tempo de compilação e, quando necessário, valide tanto o tipo quanto o intervalo de valores esperados. Testes de fuzzing e análise estática ajudam a detectar confusões de tipo.

CVE-2026-53600MEDIUMasync-tar PAX extension-header desync enables tar entry/content smugglingEPSS 0.4%CVE-2026-91731HIGHType confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandboxEPSS 0.4%CVE-2026-72766HIGHn8n before 1.123.67 Arbitrary File Read via Send Email NodeEPSS 0.4%CVE-2026-91741HIGHType confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandboEPSS 0.4%CVE-2024-13169HIGHAn out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local auEPSS 0.4%CVE-2026-58283HIGHMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.4%CVE-2026-43038CRITICALipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()EPSS 0.4%CVE-2026-79175HIGHType confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the rendEPSS 0.4%CVE-2025-13630HIGHType Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted EPSS 0.4%CVE-2025-53725HIGHWindows Push Notifications Apps Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-50155HIGHWindows Push Notifications Apps Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-93377HIGHType confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary coEPSS 0.4%CVE-2026-16363CRITICALJIT miscompilation in the JavaScript: WebAssembly componentEPSS 0.4%CVE-2025-62554HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-48815HIGHWindows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-34595MEDIUMParse Server: LiveQuery protected-field guard bypass via array-like logical operator valueEPSS 0.4%CVE-2026-58290HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-84563HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app EPSS 0.4%CVE-2026-10910HIGHType Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafEPSS 0.4%CVE-2026-74976MEDIUMJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%