VYPR

Edge

by Microsoft

Source repositories

CVEs (950)

  • CVE-2017-8724MedSep 13, 2017
    risk 0.28cvss 4.3epss 0.04

    Microsoft Edge in Microsoft Windows 10 Version 1703 allows an attacker to trick a user by redirecting the user to a specially crafted website, due to the way that Microsoft Edge parses HTTP content, aka "Microsoft Edge Spoofing Vulnerability". This CVE ID is unique from…

  • CVE-2017-8723MedSep 13, 2017
    risk 0.28cvss 4.3epss 0.04

    Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page containing malicious content, due to the way that the Edge Content Security Policy (CSP) validates certain specially crafted documents,…

  • CVE-2017-8643MedSep 13, 2017
    risk 0.28cvss 4.3epss 0.06

    Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to leave a malicious website open during user clipboard activities, due to the way that Microsoft Edge handles clipboard events, aka "Microsoft Edge Information Disclosure…

  • CVE-2017-8662MedAug 8, 2017
    risk 0.28cvss 4.3epss 0.06

    Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to disclose information due to how strings are validated in specific scenarios, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8644 and CVE-2017-8652.

  • CVE-2017-8523MedJun 15, 2017
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when Microsoft Edge fails to correctly apply Same Origin Policy for HTML elements present in other browser…

  • CVE-2017-8504MedJun 15, 2017
    risk 0.28cvss 4.3epss 0.05

    Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read the URL of a cross-origin request when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID…

  • CVE-2017-8498MedJun 15, 2017
    risk 0.28cvss 4.3epss 0.05

    Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read data not intended to be disclosed when Edge allows JavaScript XML DOM objects to detect installed browser extensions, aka "Microsoft Edge Information Disclosure Vulnerability". This…

  • CVE-2017-0231MedMay 12, 2017
    risk 0.28cvss 4.3epss 0.04

    A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Browser Spoofing Vulnerability."

  • CVE-2017-0203MedApr 12, 2017
    risk 0.28cvss 4.3epss 0.04

    A vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents. An attacker could trick a user into loading a web page with malicious content, aka "Microsoft Edge Security Feature Bypass…

  • CVE-2017-0135MedMar 17, 2017
    risk 0.28cvss 4.2epss 0.08

    Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.

  • CVE-2023-36559MedOct 13, 2023
    risk 0.27cvss 4.2epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2022-21931MedJan 11, 2022
    risk 0.27cvss 4.2epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2022-21930MedJan 11, 2022
    risk 0.27cvss 4.2epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2021-43221MedNov 24, 2021
    risk 0.27cvss 4.2epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2021-1705MedJan 12, 2021
    risk 0.27cvss 4.2epss 0.02

    Microsoft Edge (HTML-based) Memory Corruption Vulnerability

  • CVE-2020-16884MedSep 11, 2020
    risk 0.27cvss 4.2epss 0.02

    A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of…

  • CVE-2020-0663MedFeb 11, 2020
    risk 0.27cvss 4.2epss 0.02

    An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a…

  • CVE-2019-1081MedJun 12, 2019
    risk 0.27cvss 4.2epss 0.02

    An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, in a…

  • CVE-2019-1002MedJun 12, 2019
    risk 0.27cvss 4.2epss 0.02

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…

  • CVE-2016-3325LowSep 14, 2016
    risk 0.27cvss 3.1epss 0.54

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

Page 43 of 48