VYPR

Edge

by Microsoft

Source repositories

CVEs (965)

  • CVE-2026-66318HigAug 4, 2026
    risk 0.53cvss 8.1epss 0.00

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  • CVE-2024-26192HigFeb 23, 2024
    risk 0.53cvss 8.2epss 0.02

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

  • CVE-2021-31937HigJun 28, 2023
    risk 0.53cvss 8.2epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2017-11812HigOct 13, 2017
    risk 0.53cvss 7.5epss 0.48

    ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption…

  • CVE-2017-0141HigMar 17, 2017
    risk 0.53cvss 7.5epss 0.44

    A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the…

  • CVE-2016-3387HigOct 14, 2016
    risk 0.53cvss 7.5epss 0.18

    Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than…

  • CVE-2016-3259HigJul 13, 2016
    risk 0.53cvss 8.8epss 0.31

    The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 9 through 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted…

  • CVE-2016-3203HigJun 16, 2016
    risk 0.53cvss 7.8epss 0.28

    Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows PDF Remote Code Execution Vulnerability."

  • CVE-2018-8469HigSep 13, 2018
    risk 0.52cvss 7.4epss 0.13

    An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8463.

  • CVE-2018-8464HigSep 13, 2018
    risk 0.52cvss 7.5epss 0.48

    An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge PDF Remote Code Execution Vulnerability." This affects Microsoft Edge.

  • CVE-2018-8463HigSep 13, 2018
    risk 0.52cvss 7.4epss 0.13

    An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8469.

  • CVE-2017-0266HigMay 12, 2017
    risk 0.52cvss 7.5epss 0.33

    A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render when handling objects in memory, aka "Microsoft Edge Remote Code Execution Vulnerability."

  • CVE-2016-3269HigJul 13, 2016
    risk 0.52cvss 8.8epss 0.19

    The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3265.

  • CVE-2016-3265HigJul 13, 2016
    risk 0.52cvss 8.8epss 0.18

    The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3269.

  • CVE-2016-3260HigJul 13, 2016
    risk 0.52cvss 8.8epss 0.21

    The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site,…

  • CVE-2016-3199HigJun 16, 2016
    risk 0.52cvss 8.8epss 0.24

    The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3214.

  • CVE-2026-85892HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49741HigJul 1, 2025
    risk 0.51cvss 7.4epss 0.04

    No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-29795HigMar 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

  • CVE-2024-41879HigAug 26, 2024
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

Page 9 of 49