CVE-2023-42105

CVSS v3 Score
7.0
High

Vulnerability Description

Ashlar-Vellum Cobalt AR File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of AR files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-20562.

CVSS:7.0(High)

In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would...

CVSS:7.1(High)

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. An application may be able to cause unexpected syst...

CVSS:7.1(High)

Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.

CVSS:7.1(High)

Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.

CVSS:7.1(High)

Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.

CVSS:7.1(High)

Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.