VYPR

Edge

by Microsoft

Source repositories

CVEs (950)

  • CVE-2019-0678MedApr 9, 2019
    risk 0.45cvss 6.8epss 0.06

    An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a…

  • CVE-2017-0234HigMay 12, 2017
    risk 0.45cvss 7.5epss 0.38

    A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229,…

  • CVE-2016-3198MedJun 16, 2016
    risk 0.45cvss 6.5epss 0.32

    Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."

  • CVE-2026-66313MedAug 4, 2026
    risk 0.44cvss 6.8epss 0.00

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

  • CVE-2021-21140MedFeb 9, 2021
    risk 0.44cvss 6.8epss 0.01

    Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device.

  • CVE-2018-8629HigDec 12, 2018
    risk 0.44cvss 7.5epss 0.22

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8583,…

  • CVE-2018-8372HigAug 15, 2018
    risk 0.44cvss 7.5epss 0.25

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from…

  • CVE-2018-8266HigAug 15, 2018
    risk 0.44cvss 7.5epss 0.27

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8380,…

  • CVE-2017-0196MedJul 17, 2017
    risk 0.44cvss 6.5epss 0.18

    An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

  • CVE-2017-0236HigMay 12, 2017
    risk 0.44cvss 7.5epss 0.32

    A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229,…

  • CVE-2016-3374MedSep 14, 2016
    risk 0.44cvss 6.5epss 0.26

    The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a…

  • CVE-2016-3370MedSep 14, 2016
    risk 0.44cvss 6.5epss 0.22

    The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a…

  • CVE-2016-3271MedJul 13, 2016
    risk 0.44cvss 6.5epss 0.21

    The VBScript engine in Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability."

  • CVE-2016-3201MedJun 16, 2016
    risk 0.44cvss 6.5epss 0.24

    Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different…

  • CVE-2016-0191HigMay 11, 2016
    risk 0.44cvss 7.5epss 0.28

    The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0186 and…

  • CVE-2023-36008MedNov 16, 2023
    risk 0.43cvss 6.6epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2022-41115MedDec 13, 2022
    risk 0.43cvss 6.6epss 0.02

    Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability

  • CVE-2021-30621MedSep 3, 2021
    risk 0.43cvss 6.5epss 0.03

    Chromium: CVE-2021-30621 UI Spoofing in Autofill

  • CVE-2021-30619MedSep 3, 2021
    risk 0.43cvss 6.5epss 0.03

    Chromium: CVE-2021-30619 UI Spoofing in Autofill

  • CVE-2021-30617MedSep 3, 2021
    risk 0.43cvss 6.5epss 0.04

    Chromium: CVE-2021-30617 Policy bypass in Blink

Page 24 of 48