VulnSea

CWE-843

CVEs classified under CWE-843, newest first.

118 CVEsRSS

CVE-2026-61674Critical· 9.2
today

Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows

Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the …

Midnightfluent · fluent-bitvia NVD
CVE-2026-94083Critical· 9.4
yesterday

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade)

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). Thi…

MidnightOISF · SuricataEPSS 0.40%via NVD
CVE-2026-93377High· 8.8
4d ago

Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.39%via NVD
CVE-2026-91741High· 8.8
6d ago

Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.44%via NVD
CVE-2026-91731High· 8.8
6d ago

Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.44%via NVD
CVE-2026-91715High· 8.8
6d ago

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.33%via NVD
CVE-2026-91709High· 8.8
6d ago

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-92238Medium· 6.1
6d ago

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

SunlitMozilla · ThunderbirdEPSS 0.18%via NVD
CVE-2026-84602Medium· 5.5
1w ago

A type confusion issue was addressed with improved checks

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be…

Sunlitapple · ipadosEPSS 0.13%via NVD
CVE-2026-84635Medium· 6.5⚖ disputed
1w ago

A logic issue was addressed with improved state management

A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpec…

Sunlitapple · safariEPSS 0.35%via NVD
CVE-2026-84563High· 7.5
1w ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

Twilightapple · macosEPSS 0.33%via NVD
CVE-2026-65409Medium· 5.5
1w ago

A type confusion issue was addressed with improved memory handling

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An a…

Sunlitapple · ipadosEPSS 0.12%via NVD
CVE-2026-71644Critical· 9.8
1w ago

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops p…

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops p…

MidnightEPSS 0.35%via NVD
CVE-2026-45762High· 7.5
1w ago

Suricata defrag: missing address-family check can lead to remote crash

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's IP defragmentation tracker lookup did not verify that an existing tracke…

TwilightOISF · suricataEPSS 0.44%via CVEORG
CVE-2026-45764Critical· 9.1
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in S…

Midnightoisf · suricataEPSS 0.43%via NVD
CVE-2026-15461Medium· 5.3
1w ago

Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input

The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match he…

Sunlitzephyrproject · zephyrEPSS 0.16%via CVEORG
CVE-2026-87564Medium· 4.3⚖ disputed
1w ago

Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page

Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-87636High· 8.8
1w ago

Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Twilightgoogle · chromeEPSS 0.31%via NVD
CVE-2026-87612High· 8.8
1w ago

Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-87528Critical· 9.6
1w ago

Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Midnightgoogle · chromeEPSS 0.35%via NVD
CVE-2026-80161High· 7.8
1w ago

Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability t…

Twilightadobe · acrobatEPSS 0.19%via NVD
CVE-2026-81401Medium· 5.5
1w ago

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sunlitmicrosoft · 365_appsEPSS 0.50%via NVD
CVE-2026-77890High· 7.5
1w ago

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Twilightmicrosoft · windows_10_1607EPSS 0.85%via NVD
CVE-2026-77889High· 7.5
1w ago

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Twilightmicrosoft · windows_10_1607EPSS 0.85%via NVD
CVE-2026-77888High· 7.5
1w ago

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Twilightmicrosoft · windows_10_1607EPSS 0.85%via NVD
CVE-2026-77499High· 7.5
1w ago

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Twilightmicrosoft · windows_10_1607EPSS 0.85%via NVD
CVE-2026-77494High· 7.5
1w ago

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Twilightmicrosoft · windows_10_1607EPSS 1.2%via NVD
CVE-2026-72938Medium· 6.5
1w ago

Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Sunlitmicrosoft · 365_appsEPSS 0.92%via NVD
CVE-2026-70584High· 7.8
1w ago

Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.32%via NVD
CVE-2026-69717High· 8.0
1w ago

Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.

Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.70%via NVD
CWE-843 vulnerabilities (CVEs) · VulnSea