CVE-2018-6122 – chromium-browser: Type confusion in V8
https://notcve.org/view.php?id=CVE-2018-6122
Type confusion in WebAssembly in Google Chrome prior to 66.0.3359.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Una confusión de tipo en WebAssembly en Google Chrome versiones anteriores a 66.0.3359.139, permitía a un atacante remoto explotar potencialmente la corrupción de la pila por medio de una página HTML diseñada • https://crbug.com/836141 https://access.redhat.com/security/cve/CVE-2018-6122 https://bugzilla.redhat.com/show_bug.cgi?id=1577114 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2018-4953 – Adobe Acrobat Pro DC PutItemValue Type Confusion Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2018-4953
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Type Confusion vulnerability. ... Adobe Acrobat y Reader en versiones 2018.011.20038 y anteriores, 2017.011.30079 y anteriores y 2015.006.30417 y anteriores tienen una vulnerabilidad de confusión de tipos. ... The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. • http://www.securityfocus.com/bid/104173 http://www.securitytracker.com/id/1040920 https://helpx.adobe.com/security/products/acrobat/apsb18-09.html • CWE-704: Incorrect Type Conversion or Cast •
CVE-2018-0953 – Microsoft Chakra Floating Point Array Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-0953
By performing actions in JavaScript, an attacker can trigger a type confusion condition. • https://www.exploit-db.com/exploits/44694 http://www.securityfocus.com/bid/103990 http://www.securitytracker.com/id/1040844 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0953 • CWE-787: Out-of-bounds Write •
CVE-2018-8133 – Microsoft Edge Chakra - EntrySimpleObjectSlotGetter Type Confusion
https://notcve.org/view.php?id=CVE-2018-8133
Microsoft Edge Chakra suffers from an issue where EntrySimpleObjectSlotGetter can have side effects that cause a type confusion vulnerability. • https://www.exploit-db.com/exploits/44817 http://www.securityfocus.com/bid/103982 http://www.securitytracker.com/id/1040844 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8133 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •
CVE-2018-0951 – Microsoft Chakra typeof Operator Type Confusion Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2018-0951
By performing actions in JavaScript, an attacker can trigger a type confusion condition. • http://www.securityfocus.com/bid/103983 http://www.securitytracker.com/id/1040844 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0951 • CWE-787: Out-of-bounds Write •