Weaknesses of type CWE-843

686 results

Confusão de Tipos

Ocorre quando o programa trata uma variável ou objeto como se fosse de um tipo diferente do seu tipo real, levando a comportamentos impredizíveis. O atacante explora essa interpretação errada para contornar validações, corromper memória ou executar código arbitrário.

Example

Um aplicativo recebe um valor que valida como inteiro, mas a função que o processa o interpreta como um ponteiro de memória. O código tenta acessar e modificar dados no endereço apontado, causando corrupção ou exposição de informações sensíveis.

How to mitigate

Implemente validação rigorosa e conversão explícita de tipos antes de usar qualquer dado externo. Use linguagens com verificação forte de tipos em tempo de compilação e, quando necessário, valide tanto o tipo quanto o intervalo de valores esperados. Testes de fuzzing e análise estática ajudam a detectar confusões de tipo.

CVE-2026-21693HIGHiccDEV has Type Confusion in CIccSegmentedCurveXml::ToXml() at IccXML/IccLibXML/IccMpeXml.cppEPSS 0.4%CVE-2026-21692HIGHiccDEV has Type Confusion in ToXmlCurve() at IccXML/IccLibXML/IccMpeXml.cppEPSS 0.4%CVE-2026-11662HIGHType Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox viaEPSS 0.4%CVE-2026-6363HIGHType Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access vEPSS 0.4%CVE-2024-12834HIGHDelta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution VulnerabilityEPSS 0.4%CVE-2021-46878HIGHAn issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads to type confusion bug EPSS 0.4%CVE-2026-13776CRITICALType Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentiEPSS 0.3%CVE-2024-12836HIGHDelta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-14325HIGHJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.3%CVE-2026-20806MEDIUMWindows COM Server Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-69324HIGHWindows Performance Monitor Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-1847HIGHMultiple vulnerabilities exist in file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024EPSS 0.3%CVE-2026-14644HIGHNexus Repository 3 - Privilege EscalationEPSS 0.3%CVE-2026-45641HIGHWindows Hyper-V Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-26110HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-54164MEDIUMAPI Platform Core: Missing IRI type check enables resource type confusionEPSS 0.3%CVE-2023-44094—Type confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.EPSS 0.3%CVE-2026-13883CRITICALType Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.3%CVE-2026-14668HIGHPostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary readEPSS 0.3%CVE-2026-45600HIGHWindows Kernel-Mode Driver Elevation of Privilege VulnerabilityEPSS 0.3%