Edge
by Microsoft
Source repositories
CVEs (965)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-8662 | Med | 0.28 | 4.3 | 0.06 | Aug 8, 2017 | Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to disclose information due to how strings are validated in specific scenarios, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8644 and CVE-2017-8652. | ||
| CVE-2017-8523 | Med | 0.28 | 4.3 | 0.01 | Jun 15, 2017 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when Microsoft Edge fails to correctly apply Same Origin Policy for HTML elements present in other browser… | ||
| CVE-2017-8504 | Med | 0.28 | 4.3 | 0.05 | Jun 15, 2017 | Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read the URL of a cross-origin request when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID… | ||
| CVE-2017-8498 | Med | 0.28 | 4.3 | 0.05 | Jun 15, 2017 | Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read data not intended to be disclosed when Edge allows JavaScript XML DOM objects to detect installed browser extensions, aka "Microsoft Edge Information Disclosure Vulnerability". This… | ||
| CVE-2017-0231 | Med | 0.28 | 4.3 | 0.04 | May 12, 2017 | A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Browser Spoofing Vulnerability." | ||
| CVE-2017-0203 | Med | 0.28 | 4.3 | 0.04 | Apr 12, 2017 | A vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents. An attacker could trick a user into loading a web page with malicious content, aka "Microsoft Edge Security Feature Bypass… | ||
| CVE-2017-0135 | Med | 0.28 | 4.2 | 0.08 | Mar 17, 2017 | Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140. | ||
| CVE-2023-36559 | Med | 0.27 | 4.2 | 0.01 | Oct 13, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2022-21931 | Med | 0.27 | 4.2 | 0.01 | Jan 11, 2022 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2022-21930 | Med | 0.27 | 4.2 | 0.01 | Jan 11, 2022 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2021-43221 | Med | 0.27 | 4.2 | 0.01 | Nov 24, 2021 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2021-1705 | Med | 0.27 | 4.2 | 0.02 | Jan 12, 2021 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | ||
| CVE-2020-17131 | Med | 0.27 | 4.2 | 0.02 | Dec 10, 2020 | Chakra Scripting Engine Memory Corruption Vulnerability | ||
| CVE-2020-17054 | Med | 0.27 | 4.2 | 0.02 | Nov 11, 2020 | Chakra Scripting Engine Memory Corruption Vulnerability | ||
| CVE-2020-17048 | Med | 0.27 | 4.2 | 0.02 | Nov 11, 2020 | Chakra Scripting Engine Memory Corruption Vulnerability | ||
| CVE-2020-1180 | Med | 0.27 | 4.2 | 0.02 | Sep 11, 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who… | ||
| CVE-2020-1172 | Med | 0.27 | 4.2 | 0.02 | Sep 11, 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who… | ||
| CVE-2020-1057 | Med | 0.27 | 4.2 | 0.02 | Sep 11, 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who… | ||
| CVE-2020-16884 | Med | 0.27 | 4.2 | 0.02 | Sep 11, 2020 | A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of… | ||
| CVE-2020-1096 | Med | 0.27 | 4.2 | 0.02 | May 21, 2020 | A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who… |
- risk 0.28cvss 4.3epss 0.06
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to disclose information due to how strings are validated in specific scenarios, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8644 and CVE-2017-8652.
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when Microsoft Edge fails to correctly apply Same Origin Policy for HTML elements present in other browser…
- risk 0.28cvss 4.3epss 0.05
Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read the URL of a cross-origin request when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID…
- risk 0.28cvss 4.3epss 0.05
Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read data not intended to be disclosed when Edge allows JavaScript XML DOM objects to detect installed browser extensions, aka "Microsoft Edge Information Disclosure Vulnerability". This…
- risk 0.28cvss 4.3epss 0.04
A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Browser Spoofing Vulnerability."
- risk 0.28cvss 4.3epss 0.04
A vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents. An attacker could trick a user into loading a web page with malicious content, aka "Microsoft Edge Security Feature Bypass…
- risk 0.28cvss 4.2epss 0.08
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.27cvss 4.2epss 0.02
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
- risk 0.27cvss 4.2epss 0.02
Chakra Scripting Engine Memory Corruption Vulnerability
- risk 0.27cvss 4.2epss 0.02
Chakra Scripting Engine Memory Corruption Vulnerability
- risk 0.27cvss 4.2epss 0.02
Chakra Scripting Engine Memory Corruption Vulnerability
- risk 0.27cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who…
- risk 0.27cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who…
- risk 0.27cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who…
- risk 0.27cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of…
- risk 0.27cvss 4.2epss 0.02
A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who…
Page 44 of 49