VYPR

Edge

by Microsoft

Source repositories

CVEs (965)

  • CVE-2020-0878MedKEVSep 11, 2020
    risk 0.46cvss 4.2epss 0.03

    A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully…

  • CVE-2020-1073HigJun 9, 2020
    risk 0.46cvss 8.1epss 0.09

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.

  • CVE-2019-0649HigMar 5, 2019
    risk 0.46cvss 8.1epss 0.05

    A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileged Vulnerability'.

  • CVE-2024-21388MedJan 30, 2024
    risk 0.45cvss 6.5epss 0.32

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2019-0678MedApr 9, 2019
    risk 0.45cvss 6.8epss 0.05

    An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a…

  • CVE-2017-0234HigMay 12, 2017
    risk 0.45cvss 7.5epss 0.36

    A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229,…

  • CVE-2016-3198MedJun 16, 2016
    risk 0.45cvss 6.5epss 0.30

    Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."

  • CVE-2026-66313MedAug 4, 2026
    risk 0.44cvss 6.8epss 0.00

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

  • CVE-2021-21140MedFeb 9, 2021
    risk 0.44cvss 6.8epss 0.01

    Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device.

  • CVE-2018-8372HigAug 15, 2018
    risk 0.44cvss 7.5epss 0.24

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from…

  • CVE-2018-8266HigAug 15, 2018
    risk 0.44cvss 7.5epss 0.24

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8380,…

  • CVE-2017-0196MedJul 17, 2017
    risk 0.44cvss 6.5epss 0.14

    An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

  • CVE-2017-0236HigMay 12, 2017
    risk 0.44cvss 7.5epss 0.30

    A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229,…

  • CVE-2016-3382HigOct 14, 2016
    risk 0.44cvss 7.5epss 0.22

    The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by the Chakra JavaScript engine, aka "Scripting Engine…

  • CVE-2016-3374MedSep 14, 2016
    risk 0.44cvss 6.5epss 0.21

    The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a…

  • CVE-2016-3370MedSep 14, 2016
    risk 0.44cvss 6.5epss 0.18

    The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a…

  • CVE-2016-3271MedJul 13, 2016
    risk 0.44cvss 6.5epss 0.17

    The VBScript engine in Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability."

  • CVE-2016-3201MedJun 16, 2016
    risk 0.44cvss 6.5epss 0.19

    Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different…

  • CVE-2016-0191HigMay 11, 2016
    risk 0.44cvss 7.5epss 0.26

    The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0186 and…

  • CVE-2023-36008MedNov 16, 2023
    risk 0.43cvss 6.6epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Page 24 of 49