Medium severity4.3NVD Advisory· Published Apr 12, 2017· Updated Jun 17, 2026
CVE-2017-0208
CVE-2017-0208
Description
An information disclosure vulnerability exists in Microsoft Edge when the Chakra scripting engine does not properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, a.k.a. "Scripting Engine Information Disclosure Vulnerability."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.ChakraCoreNuGet | < 1.4.3 | 1.4.3 |
Affected products
3Patches
Vulnerability mechanics
References
9- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0208nvdPatchVendor AdvisoryWEB
- www.securityfocus.com/bid/97460nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-pjpr-2qqp-gprfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-0208ghsaADVISORY
- github.com/chakra-core/ChakraCore/commit/54d6d085987e2c399863940179db67b594d7f0a3ghsaWEB
- github.com/chakra-core/ChakraCore/pull/2834ghsaWEB
- web.archive.org/web/20210124023848/http://www.securityfocus.com/bid/97460ghsaWEB
- web.archive.org/web/20211201121401/http://www.securitytracker.com/id/1038234ghsaWEB
- www.securitytracker.com/id/1038234nvd
News mentions
0No linked articles in our index yet.