Weaknesses of type CWE-843

686 results

Confusão de Tipos

Ocorre quando o programa trata uma variável ou objeto como se fosse de um tipo diferente do seu tipo real, levando a comportamentos impredizíveis. O atacante explora essa interpretação errada para contornar validações, corromper memória ou executar código arbitrário.

Example

Um aplicativo recebe um valor que valida como inteiro, mas a função que o processa o interpreta como um ponteiro de memória. O código tenta acessar e modificar dados no endereço apontado, causando corrupção ou exposição de informações sensíveis.

How to mitigate

Implemente validação rigorosa e conversão explícita de tipos antes de usar qualquer dado externo. Use linguagens com verificação forte de tipos em tempo de compilação e, quando necessário, valide tanto o tipo quanto o intervalo de valores esperados. Testes de fuzzing e análise estática ajudam a detectar confusões de tipo.

CVE-2023-6045MEDIUMArkruntime has a type confusion vulnerabilityEPSS 0.2%CVE-2023-37376HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2025-66586HIGHType Confusion vulnerability in AzeoTech DAQFactoryEPSS 0.2%CVE-2026-8554LOWType Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer proceEPSS 0.2%CVE-2025-7230HIGHINVT VT-Designer PM3 File Parsing Type Confusion Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-21330HIGHAfter Effects | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)EPSS 0.2%CVE-2023-28729HIGHA type confusion vulnerability in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution EPSS 0.2%CVE-2026-59304LOWImproper caching of the original content type in Spring Cloud Stream AvroEPSS 0.2%CVE-2023-41075HIGHA type confusion issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and iPaEPSS 0.2%CVE-2023-46705MEDIUMArkruntime has a type confusion vulnerabilityEPSS 0.2%CVE-2025-7999HIGHAshlar-Vellum Cobalt AR File Parsing Type Confusion Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-26496CRITICALAccess of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux EPSS 0.2%CVE-2026-17866MEDIUMType Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process EPSS 0.2%CVE-2025-43236LOWA type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS VeEPSS 0.2%CVE-2025-8002HIGHAshlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-8000HIGHAshlar-Vellum Cobalt LI File Parsing Type Confusion Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-8005HIGHAshlar-Vellum Cobalt XE File Parsing Type Confusion Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-7995HIGHAshlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution VulnerabilityEPSS 0.2%CVE-2023-3022MEDIUMA flaw was found in the IPv6 module of the Linux kernel. The arg.result was not used consistently in fib6_rule_lookup, sometimes holding rt6EPSS 0.2%CVE-2026-59152MEDIUMArbitrary server-side file read in LangSmith SDK TracingMiddlewareEPSS 0.2%