Threats Tagged 'cwe-843'
View all threats tagged with 'cwe-843'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-843'
Click on any threat for detailed analysis and mitigation recommendations
Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6, from 6.1.2.21 before 6.1.*. Join the discussion | CVE Database V5 | 09/22/2026, 17:50:17 UTC Added: 09/22/2026, 18:03:27 UTC |
Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6. Join the discussion | CVE Database V5 | 09/22/2026, 17:50:16 UTC Added: 09/22/2026, 18:03:26 UTC |
Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the 32-byte stack buffer msg with memcpy without checking its MessagePack type or length. An attacker who controls or can impersonate an out_forward Secure Forward destination configured with Shared_Key or Empty_Shared_Key can send an oversized reason during the first handshake and overwrite stack control data. Protected builds reliably terminate, while builds without a stack canary or with a disclosure can allow remote code execution as the Fluent Bit process user. When the opt-in --supervisor mode is used, fork-only respawns preserve the canary and address layout, allowing repeated crash-or-survive probes to support code execution on a hardened build; ordinary exec-based or service-manager restarts do not preserve that state. This issue is fixed in version 5.0.8. Join the discussion | CVE Database V5 | 09/21/2026, 16:10:15 UTC Added: 09/21/2026, 16:33:23 UTC |
0 Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions. Join the discussion | CVE Database V5 | 09/20/2026, 01:18:05 UTC Added: 09/20/2026, 01:32:11 UTC |
0 CVE-2026-45764 is a critical vulnerability in Suricata, a network intrusion detection and prevention system. The flaw involves a type confusion issue triggered by a protocol change while processing HTTP/2 traffic. This can cause Suricata to crash, resulting in a denial of service. Versions prior to 7.0.16 and 8.0.5 are affected. Fixed versions 7.0.16 and 8.0.5 address this issue. Disabling HTTP/2 parsing is a recommended workaround if that functionality is not needed. Join the discussion | CVE Database V5 | 09/10/2026, 21:14:30 UTC Added: 09/10/2026, 21:32:23 UTC |
0 CVE-2026-45762 is a high-severity vulnerability in Suricata, a network intrusion detection and prevention system. The flaw involves a type confusion in the IP defragmentation tracker lookup, where fragmented IPv6 packets could be incorrectly associated with IPv4 trackers. This mismatch can cause Suricata to crash and result in a denial of service. The issue affects Suricata versions prior to 7.0.16 and versions from 8.0.0 up to but not including 8.0.5. Fixed versions 7.0.16 and 8.0.5 address this vulnerability. A workaround for IDS deployments using AF_PACKET is to enable the AF_PACKET defrag option to prevent Suricata from processing problematic fragmented packets. Join the discussion | CVE Database V5 | 09/10/2026, 21:09:21 UTC Added: 09/10/2026, 21:32:23 UTC |
0 Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Join the discussion | CVE Database V5 | 09/08/2026, 20:30:58 UTC Added: 09/08/2026, 20:38:09 UTC |
0 CVE-2026-81401 is a medium severity vulnerability in Microsoft Office Excel within Microsoft 365 Apps for Enterprise. It involves a type confusion flaw that allows an unauthorized local attacker to disclose information. The vulnerability requires user interaction and low attack complexity. An official fix is available from Microsoft. Join the discussion | CVE Database V5 | 09/08/2026, 17:18:57 UTC Added: 09/08/2026, 17:27:13 UTC |
0 Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 09/08/2026, 17:17:42 UTC Added: 09/08/2026, 17:26:28 UTC |
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. Join the discussion | CVE Database V5 | 09/08/2026, 17:16:21 UTC Added: 09/08/2026, 17:25:49 UTC |
Showing 1 to 10 of 192 results