Patch & vulnerability status
Microsoft Edge 151.0.4129.59
Latest tracked version 151.0.4129.59. Release status, tracked CVEs, and automated cross-platform patching for Microsoft Edge.
| Platform | Latest version | CVEs tracked | Last checked |
|---|---|---|---|
| Linux | 151.0.4129.59 | 0 | 2026-08-10 |
| Mac | 151.0.4129.59 | 0 | 2026-08-10 |
| Windows | 148.0.3967 | 979 | 2026-04-07 |
| Windows | 151.0.4129.59 | 979 | 2026-08-10 |
Known vulnerabilities (CVEs) in Microsoft Edge
Lavawall tracks 979 published CVEs affecting Microsoft Edge, and deploys the versions that fix them automatically across your fleet.
| CVE | Published | Severity | Details | Vector |
|---|---|---|---|---|
| CVE-2026-66326 | 2026-08-04 00:17:40 | MEDIUM (7) | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-66325 | 2026-08-04 00:17:40 | MEDIUM (6) | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-66322 | 2026-08-04 00:17:40 | HIGH (7) | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-66321 | 2026-08-04 00:17:39 | HIGH (7) | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-66318 | 2026-08-04 00:17:39 | HIGH (8) | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | NETWORK |
| CVE-2026-66317 | 2026-08-04 00:17:39 | MEDIUM (5) | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. | NETWORK |
| CVE-2026-66316 | 2026-08-04 00:17:39 | MEDIUM (5) | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-66315 | 2026-08-04 00:17:39 | HIGH (8) | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-66314 | 2026-08-04 00:17:39 | MEDIUM (7) | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | NETWORK |
| CVE-2026-66313 | 2026-08-04 00:17:39 | MEDIUM (7) | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | LOCAL |
| CVE-2026-66312 | 2026-08-04 00:17:39 | MEDIUM (7) | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | NETWORK |
| CVE-2026-66311 | 2026-08-04 00:17:38 | MEDIUM (6) | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | LOCAL |
| CVE-2026-66310 | 2026-08-04 00:17:38 | HIGH (8) | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | LOCAL |
| CVE-2026-65804 | 2026-08-04 00:17:38 | MEDIUM (6) | Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-65802 | 2026-08-04 00:17:38 | HIGH (7) | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. | NETWORK |
| CVE-2026-62828 | 2026-07-28 16:19:42 | MEDIUM (5) | Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. | NETWORK |
| CVE-2026-58597 | 2026-07-03 21:17:06 | MEDIUM (4) | Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-58596 | 2026-07-12 16:16:31 | HIGH (8) | Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | NETWORK |
| CVE-2026-58525 | 2026-07-08 21:16:54 | HIGH (8) | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | NETWORK |
| CVE-2026-58524 | 2026-07-03 21:17:06 | MEDIUM (5) | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-58523 | 2026-07-03 22:16:56 | MEDIUM (7) | Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. | NETWORK |
| CVE-2026-58522 | 2026-07-03 21:17:06 | MEDIUM (7) | Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | LOCAL |
| CVE-2026-58300 | 2026-07-03 21:17:05 | MEDIUM (6) | Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | LOCAL |
| CVE-2026-58299 | 2026-07-03 21:17:05 | HIGH (8) | Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-58298 | 2026-07-03 21:17:05 | HIGH (7) | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-58297 | 2026-07-03 21:17:05 | HIGH (7) | Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. | NETWORK |
| CVE-2026-58296 | 2026-07-03 21:17:05 | HIGH (7) | Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. | NETWORK |
| CVE-2026-58295 | 2026-07-03 21:17:04 | HIGH (8) | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | NETWORK |
| CVE-2026-58294 | 2026-07-03 21:17:04 | HIGH (8) | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-58293 | 2026-07-03 21:17:04 | HIGH (8) | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-58292 | 2026-07-03 21:17:04 | HIGH (8) | Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-58291 | 2026-07-03 21:17:04 | MEDIUM (6) | Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | NETWORK |
| CVE-2026-58290 | 2026-07-03 21:17:04 | HIGH (8) | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-58289 | 2026-07-03 21:17:04 | CRITICAL (9) | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-58288 | 2026-07-03 21:17:04 | HIGH (8) | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-58287 | 2026-07-03 21:17:03 | HIGH (8) | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-58286 | 2026-07-03 21:17:03 | HIGH (8) | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-58285 | 2026-07-03 21:17:03 | HIGH (8) | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-58284 | 2026-07-03 21:17:03 | HIGH (8) | Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-58283 | 2026-07-03 21:17:03 | HIGH (8) | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-58282 | 2026-07-03 21:17:03 | HIGH (8) | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-58281 | 2026-07-11 21:16:24 | HIGH (8) | Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-58278 | 2026-07-03 21:17:03 | MEDIUM (5) | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-58276 | 2026-07-03 21:17:03 | HIGH (8) | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-57993 | 2026-07-03 21:17:02 | HIGH (7) | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-57992 | 2026-07-03 21:17:02 | HIGH (8) | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-57991 | 2026-07-03 21:17:02 | HIGH (7) | Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | NETWORK |
| CVE-2026-57990 | 2026-07-26 18:18:25 | HIGH (7) | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | NETWORK |
| CVE-2026-57989 | 2026-07-26 18:18:25 | HIGH (7) | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | NETWORK |
| CVE-2026-57988 | 2026-07-03 21:17:02 | HIGH (7) | Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-57987 | 2026-07-03 21:17:02 | MEDIUM (7) | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-57986 | 2026-07-03 21:17:02 | HIGH (8) | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-57985 | 2026-07-03 21:17:02 | HIGH (8) | Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-57984 | 2026-07-03 21:17:02 | HIGH (8) | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-57983 | 2026-07-03 21:17:01 | HIGH (9) | Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | NETWORK |
| CVE-2026-57981 | 2026-07-03 21:17:01 | HIGH (9) | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-57980 | 2026-07-17 22:18:00 | MEDIUM (5) | Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. | NETWORK |
| CVE-2026-57978 | 2026-07-26 18:18:24 | MEDIUM (5) | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-57977 | 2026-07-03 21:17:01 | HIGH (7) | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-57975 | 2026-07-03 21:17:01 | HIGH (8) | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-57974 | 2026-07-03 21:17:01 | HIGH (9) | Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-56646 | 2026-07-03 21:17:01 | MEDIUM (7) | Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-56645 | 2026-07-03 21:17:01 | HIGH (9) | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2026-55945 | 2026-07-03 21:17:01 | MEDIUM (4) | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally. | LOCAL |
| CVE-2026-50521 | 2026-07-01 21:17:03 | HIGH (8) | Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | NETWORK |
| CVE-2026-45495 | 2026-05-18 18:17:39 | HIGH (9) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2026-45494 | 2026-05-18 18:17:38 | MEDIUM (5) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2026-45492 | 2026-05-18 18:17:38 | MEDIUM (5) | Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | NETWORK |
| CVE-2026-45489 | 2026-07-03 21:17:00 | MEDIUM (7) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2026-45488 | 2026-07-03 21:17:00 | MEDIUM (5) | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-45173 | 2026-06-11 22:16:57 | HIGH (8) | Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21 | NETWORK |
| CVE-2026-42891 | 2026-05-12 18:17:26 | MEDIUM (7) | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-42838 | 2026-05-12 18:17:26 | MEDIUM (5) | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | NETWORK |
| CVE-2026-41107 | 2026-05-12 18:17:22 | HIGH (7) | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | NETWORK |
| CVE-2026-40416 | 2026-05-12 18:17:20 | MEDIUM (4) | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-35429 | 2026-05-12 18:17:14 | MEDIUM (4) | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-33119 | 2026-04-10 22:16:21 | MEDIUM (5) | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-33118 | 2026-04-10 22:16:21 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2026-32208 | 2026-06-19 21:16:42 | HIGH (9) | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-21223 | 2026-01-16 22:16:26 | HIGH (7) | Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. | LOCAL |
| CVE-2026-0391 | 2026-02-05 23:15:54 | MEDIUM (7) | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2026-0385 | 2026-03-16 14:18:07 | MEDIUM (5) | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | NETWORK |
| CVE-2025-65046 | 2025-12-18 22:16:02 | LOW (3) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2025-62224 | 2026-01-07 23:15:44 | MEDIUM (6) | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2025-62223 | 2025-12-05 01:15:49 | MEDIUM (4) | User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2025-60711 | 2025-10-31 20:15:52 | MEDIUM (6) | Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2025-59251 | 2025-09-24 19:15:42 | HIGH (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2025-5419 | 2025-06-03 00:15:21 | HIGH (9) | Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2025-53791 | 2025-09-05 21:15:39 | MEDIUM (5) | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | NETWORK |
| CVE-2025-49755 | 2025-08-12 18:15:31 | MEDIUM (4) | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2025-49741 | 2025-07-01 23:15:31 | HIGH (7) | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | NETWORK |
| CVE-2025-49736 | 2025-08-12 18:15:30 | MEDIUM (4) | The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2025-49713 | 2025-07-02 18:15:24 | HIGH (9) | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2025-47967 | 2025-09-16 19:15:35 | MEDIUM (5) | Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2025-47964 | 2025-07-11 17:15:40 | MEDIUM (5) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2025-47963 | 2025-07-11 17:15:40 | MEDIUM (6) | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2025-47182 | 2025-07-11 17:15:39 | MEDIUM (6) | Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. | LOCAL |
| CVE-2025-29834 | 2025-04-12 02:15:22 | HIGH (8) | Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2025-29825 | 2025-05-02 02:15:16 | MEDIUM (7) | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2025-29815 | 2025-04-04 01:15:39 | HIGH (8) | Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | NETWORK |
| CVE-2025-29806 | 2025-03-23 17:15:29 | MEDIUM (7) | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2025-29796 | 2025-04-04 01:15:39 | MEDIUM (5) | User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2025-26643 | 2025-03-07 19:15:37 | MEDIUM (5) | The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2025-25001 | 2025-04-04 01:15:39 | MEDIUM (4) | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | NETWORK |
| CVE-2025-25000 | 2025-04-04 01:15:38 | HIGH (9) | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | NETWORK |
| CVE-2025-21408 | 2025-02-06 23:15:10 | HIGH (9) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2025-21404 | 2025-02-06 23:15:10 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2025-21401 | 2025-02-15 00:15:27 | MEDIUM (5) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | LOCAL |
| CVE-2025-21342 | 2025-02-06 23:15:09 | HIGH (9) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2025-21283 | 2025-02-06 23:15:09 | MEDIUM (7) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2025-21279 | 2025-02-06 23:15:09 | MEDIUM (7) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2025-21267 | 2025-02-06 23:15:09 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | LOCAL |
| CVE-2025-21262 | 2025-01-24 22:15:38 | MEDIUM (5) | User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network | NETWORK |
| CVE-2025-21253 | 2025-02-06 23:15:09 | MEDIUM (5) | Microsoft Edge for IOS and Android Spoofing Vulnerability | NETWORK |
| CVE-2025-21185 | 2025-01-17 20:15:30 | MEDIUM (7) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2025-14174 | 2025-12-12 20:15:40 | HIGH (9) | Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2024-7971 | 2024-08-21 21:15:09 | CRITICAL (10) | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2024-7965 | 2024-08-21 21:15:09 | HIGH (9) | Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2024-49054 | 2024-11-22 15:15:14 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-49041 | 2024-12-06 02:15:18 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-49025 | 2024-11-14 20:15:25 | MEDIUM (5) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2024-49023 | 2024-10-18 01:15:41 | MEDIUM (6) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2024-43596 | 2024-10-17 23:15:17 | MEDIUM (9) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2024-43595 | 2024-10-17 23:15:16 | MEDIUM (9) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2024-43587 | 2024-10-17 23:15:16 | MEDIUM (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2024-43580 | 2024-10-17 23:15:16 | MEDIUM (5) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-43579 | 2024-10-17 23:15:16 | HIGH (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2024-43578 | 2024-10-17 23:15:15 | HIGH (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2024-43577 | 2024-10-18 23:15:07 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-43566 | 2024-10-17 23:15:15 | HIGH (10) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2024-43496 | 2024-09-19 21:15:16 | MEDIUM (9) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2024-43489 | 2024-09-19 21:15:16 | MEDIUM (9) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2024-43472 | 2024-08-16 20:15:14 | MEDIUM (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2024-38222 | 2024-09-12 03:15:03 | MEDIUM (7) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2024-38221 | 2024-09-19 21:15:14 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-38219 | 2024-08-12 13:38:24 | MEDIUM (9) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2024-38218 | 2024-08-12 13:38:24 | HIGH (8) | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | LOCAL |
| CVE-2024-38210 | 2024-08-22 23:15:08 | HIGH (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | LOCAL |
| CVE-2024-38209 | 2024-08-22 23:15:08 | HIGH (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | LOCAL |
| CVE-2024-38208 | 2024-08-22 23:15:08 | MEDIUM (6) | Microsoft Edge for Android Spoofing Vulnerability | NETWORK |
| CVE-2024-38207 | 2024-08-23 23:15:08 | MEDIUM (6) | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | NETWORK |
| CVE-2024-38156 | 2024-07-19 02:15:18 | MEDIUM (6) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-38103 | 2024-07-25 22:15:08 | MEDIUM (6) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2024-38093 | 2024-06-20 20:15:19 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-38083 | 2024-06-13 20:15:15 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-38082 | 2024-06-20 20:15:18 | MEDIUM (5) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-30058 | 2024-06-13 20:15:13 | MEDIUM (5) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-30057 | 2024-06-13 20:15:12 | MEDIUM (5) | Microsoft Edge for iOS Spoofing Vulnerability | NETWORK |
| CVE-2024-30056 | 2024-05-25 18:15:13 | HIGH (7) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2024-30055 | 2024-05-14 15:21:51 | MEDIUM (5) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-29991 | 2024-04-19 17:15:54 | MEDIUM (5) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2024-29987 | 2024-04-18 19:15:11 | MEDIUM (7) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2024-29986 | 2024-04-18 19:15:11 | MEDIUM (5) | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2024-29981 | 2024-04-04 22:15:09 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-29057 | 2024-03-22 22:15:50 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-29049 | 2024-04-04 22:15:09 | MEDIUM (4) | Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability | LOCAL |
| CVE-2024-26247 | 2024-03-22 22:15:50 | MEDIUM (5) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2024-26246 | 2024-03-14 23:15:46 | LOW (4) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | PHYSICAL |
| CVE-2024-26196 | 2024-03-21 02:52:17 | MEDIUM (4) | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2024-26192 | 2024-02-23 23:15:10 | HIGH (8) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2024-26188 | 2024-02-23 23:15:10 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2024-26167 | 2024-03-07 21:15:08 | MEDIUM (4) | Microsoft Edge for Android Spoofing Vulnerability | NETWORK |
| CVE-2024-26163 | 2024-03-14 23:15:46 | MEDIUM (5) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2024-21423 | 2024-02-23 22:15:55 | MEDIUM (5) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2024-21399 | 2024-02-02 01:15:09 | HIGH (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2024-21388 | 2024-01-30 18:15:48 | MEDIUM (7) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2024-21387 | 2024-01-26 01:15:11 | MEDIUM (5) | Microsoft Edge for Android Spoofing Vulnerability | NETWORK |
| CVE-2024-21385 | 2024-01-26 01:15:11 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2024-21383 | 2024-01-26 01:15:10 | LOW (3) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | LOCAL |
| CVE-2024-21382 | 2024-01-26 01:15:10 | MEDIUM (4) | Microsoft Edge for Android Information Disclosure Vulnerability | NETWORK |
| CVE-2024-21337 | 2024-01-11 22:15:47 | MEDIUM (5) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | LOCAL |
| CVE-2024-21336 | 2024-01-26 18:15:12 | LOW (3) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | LOCAL |
| CVE-2024-21326 | 2024-01-26 01:15:10 | CRITICAL (10) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2024-20675 | 2024-01-11 21:15:13 | MEDIUM (6) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2023-6702 | 2023-12-14 22:15:44 | HIGH (9) | Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2023-6345 | 2023-11-29 12:15:07 | CRITICAL (10) | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) | NETWORK |
| CVE-2023-5217 | 2023-09-28 16:15:11 | HIGH (9) | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2023-4863 | 2023-09-12 15:15:24 | HIGH (9) | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) | NETWORK |
| CVE-2023-4762 | 2023-09-05 22:15:10 | HIGH (9) | Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2023-44323 | 2023-10-30 15:15:41 | MEDIUM (6) | Adobe Acrobat for Edge version 118.0.2088.46 (and earlier) is affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | LOCAL |
| CVE-2023-38187 | 2023-07-21 18:15:10 | MEDIUM (7) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2023-38174 | 2023-12-07 21:15:08 | MEDIUM (4) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2023-38173 | 2023-07-21 18:15:10 | MEDIUM (4) | Microsoft Edge for Android Spoofing Vulnerability | NETWORK |
| CVE-2023-38158 | 2023-08-21 20:15:09 | LOW (3) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2023-38157 | 2023-08-07 18:15:10 | MEDIUM (7) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2023-36888 | 2023-07-14 18:15:11 | MEDIUM (6) | Microsoft Edge for Android (Chromium-based) Tampering Vulnerability | NETWORK |
| CVE-2023-36887 | 2023-07-14 18:15:11 | HIGH (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | LOCAL |
| CVE-2023-36883 | 2023-07-14 18:15:11 | MEDIUM (4) | Microsoft Edge for iOS Spoofing Vulnerability | NETWORK |
| CVE-2023-36880 | 2023-12-07 21:15:08 | MEDIUM (5) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2023-36878 | 2023-12-15 01:15:08 | MEDIUM (4) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2023-36787 | 2023-08-21 20:15:09 | HIGH (9) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2023-36741 | 2023-08-26 01:15:08 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2023-36735 | 2023-09-15 22:15:14 | CRITICAL (10) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2023-36727 | 2023-09-15 22:15:14 | MEDIUM (6) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2023-36562 | 2023-09-15 22:15:13 | HIGH (7) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2023-36559 | 2023-10-13 21:15:52 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2023-36409 | 2023-11-07 00:15:08 | MEDIUM (7) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2023-36034 | 2023-11-03 01:15:08 | HIGH (7) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | LOCAL |
| CVE-2023-36029 | 2023-11-03 01:15:08 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2023-36027 | 2023-11-10 20:15:07 | MEDIUM (7) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2023-36026 | 2023-11-16 20:15:28 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2023-36024 | 2023-11-10 00:15:09 | HIGH (7) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2023-36022 | 2023-11-03 01:15:08 | MEDIUM (7) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | LOCAL |
| CVE-2023-36014 | 2023-11-10 00:15:09 | HIGH (7) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | LOCAL |
| CVE-2023-36008 | 2023-11-16 20:15:28 | MEDIUM (7) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | LOCAL |
| CVE-2023-35618 | 2023-12-07 21:15:07 | CRITICAL (10) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2023-35392 | 2023-07-21 18:15:10 | MEDIUM (5) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2023-33145 | 2023-06-14 00:15:13 | MEDIUM (7) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2023-33143 | 2023-06-03 01:15:37 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2023-29354 | 2023-05-05 23:15:09 | MEDIUM (5) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2023-29350 | 2023-05-05 23:15:09 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2023-29345 | 2023-06-07 18:15:10 | MEDIUM (6) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2023-29334 | 2023-04-28 18:15:26 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2023-28301 | 2023-04-11 21:15:28 | LOW (4) | Microsoft Edge (Chromium-based) Tampering Vulnerability | NETWORK |
| CVE-2023-28286 | 2023-04-27 19:15:20 | MEDIUM (6) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2023-28284 | 2023-04-11 21:15:27 | MEDIUM (4) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2023-28261 | 2023-04-27 19:15:20 | MEDIUM (6) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | LOCAL |
| CVE-2023-24935 | 2023-04-11 21:15:21 | MEDIUM (6) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2023-24892 | 2023-03-14 17:15:18 | HIGH (8) | Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability | NETWORK |
| CVE-2023-23374 | 2023-02-14 20:15:17 | HIGH (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2023-21796 | 2023-01-24 00:15:11 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2023-21795 | 2023-01-24 00:15:11 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2023-21794 | 2023-02-14 20:15:15 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2023-21775 | 2023-01-24 00:15:11 | HIGH (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2023-21720 | 2023-02-14 20:15:15 | MEDIUM (5) | Microsoft Edge (Chromium-based) Tampering Vulnerability | NETWORK |
| CVE-2023-21719 | 2023-01-24 00:15:10 | MEDIUM (7) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2022-44708 | 2022-12-13 19:15:15 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-44688 | 2022-12-13 19:15:14 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2022-4135 | 2022-11-25 01:15:10 | CRITICAL (10) | Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | NETWORK |
| CVE-2022-41115 | 2022-12-13 19:15:12 | MEDIUM (7) | Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-41035 | 2022-10-11 19:15:21 | MEDIUM (5) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2022-38012 | 2022-09-13 19:15:13 | HIGH (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | LOCAL |
| CVE-2022-35796 | 2022-08-09 20:15:14 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-33680 | 2022-07-07 20:15:08 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-33649 | 2022-08-09 20:15:10 | CRITICAL (10) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2022-33639 | 2022-06-29 17:15:08 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-33638 | 2022-06-29 17:15:08 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-33636 | 2022-08-09 20:15:10 | HIGH (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2022-30192 | 2022-06-29 17:15:08 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-30128 | 2022-06-01 20:15:08 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-30127 | 2022-06-01 20:15:08 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-29147 | 2023-06-29 01:15:50 | LOW (3) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2022-29146 | 2023-06-29 01:15:50 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-29144 | 2023-06-29 01:15:50 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-26912 | 2022-04-05 20:15:09 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-26909 | 2022-04-05 20:15:09 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-26908 | 2022-04-05 20:15:09 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-26905 | 2022-06-01 20:15:08 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2022-26900 | 2022-04-05 20:15:09 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-26899 | 2023-06-29 02:15:16 | MEDIUM (9) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-26895 | 2022-04-05 20:15:09 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-26894 | 2022-04-05 20:15:09 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-26891 | 2022-04-05 20:15:09 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-24523 | 2022-04-05 20:15:09 | MEDIUM (4) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2022-24475 | 2022-04-05 20:15:09 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-23264 | 2023-06-29 05:15:13 | MEDIUM (5) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2022-23263 | 2022-02-07 17:15:13 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | LOCAL |
| CVE-2022-23262 | 2022-02-07 17:15:13 | MEDIUM (6) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-23261 | 2022-02-07 17:15:13 | MEDIUM (5) | Microsoft Edge (Chromium-based) Tampering Vulnerability | NETWORK |
| CVE-2022-23258 | 2022-01-25 22:15:08 | MEDIUM (4) | Microsoft Edge for Android Spoofing Vulnerability | NETWORK |
| CVE-2022-22021 | 2022-06-15 22:15:13 | HIGH (8) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2022-21970 | 2022-01-11 21:15:15 | MEDIUM (6) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | LOCAL |
| CVE-2022-21954 | 2022-01-11 21:15:14 | MEDIUM (6) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2022-21931 | 2022-01-11 21:15:14 | MEDIUM (4) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2022-21930 | 2022-01-11 21:15:14 | MEDIUM (4) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2022-21929 | 2022-01-11 21:15:14 | LOW (3) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | LOCAL |
| CVE-2021-43221 | 2021-11-24 01:15:09 | MEDIUM (4) | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | NETWORK |
| CVE-2021-42308 | 2021-11-24 01:15:08 | LOW (3) | Microsoft Edge (Chromium-based) Spoofing Vulnerability | NETWORK |
| CVE-2021-42307 | 2023-07-01 00:15:10 | MEDIUM (4) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | NETWORK |
| CVE-2021-41351 | 2021-11-10 01:19:29 | MEDIUM (4) | Microsoft Edge (Chrome based) Spoofing on IE Mode | NETWORK |
| CVE-2021-38669 | 2021-09-15 12:15:16 | MEDIUM (6) | Microsoft Edge (Chromium-based) Tampering Vulnerability | NETWORK |
| CVE-2021-38642 | 2021-09-02 23:15:07 | MEDIUM (6) | Microsoft Edge for iOS Spoofing Vulnerability | NETWORK |
| CVE-2021-38641 | 2021-09-02 23:15:07 | MEDIUM (6) | Microsoft Edge for Android Spoofing Vulnerability | NETWORK |
| CVE-2021-36931 | 2021-08-26 18:15:09 | MEDIUM (4) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | LOCAL |
| CVE-2021-36930 | 2021-09-02 23:15:07 | MEDIUM (5) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | LOCAL |
| CVE-2021-36929 | 2021-08-26 18:15:09 | MEDIUM (6) | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | LOCAL |
| CVE-2021-36928 | 2021-08-26 18:15:09 | MEDIUM (6) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | LOCAL |
| CVE-2021-34506 | 2023-07-01 00:15:10 | MEDIUM (6) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2021-34475 | 2023-07-01 00:15:10 | MEDIUM (5) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2021-33741 | 2021-06-08 23:15:10 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2021-31982 | 2023-07-01 00:15:10 | HIGH (9) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2021-31937 | 2023-06-28 18:15:12 | HIGH (8) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2021-26439 | 2021-09-02 23:15:07 | MEDIUM (5) | Microsoft Edge for Android Information Disclosure Vulnerability | PHYSICAL |
| CVE-2021-26436 | 2021-09-02 23:15:07 | MEDIUM (6) | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | NETWORK |
| CVE-2021-24113 | 2021-02-25 23:15:17 | MEDIUM (5) | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | NETWORK |
| CVE-2021-24100 | 2021-02-25 23:15:16 | MEDIUM (5) | Microsoft Edge for Android Information Disclosure Vulnerability | LOCAL |
| CVE-2021-21157 | 2021-02-22 22:15:13 | HIGH (9) | Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | NETWORK |
| CVE-2021-21141 | 2021-02-09 14:15:17 | MEDIUM (7) | Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy via a crafted HTML page. | NETWORK |
| CVE-2021-21140 | 2021-02-09 14:15:17 | MEDIUM (7) | Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device. | PHYSICAL |
| CVE-2021-21139 | 2021-02-09 14:15:17 | MEDIUM (7) | Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | NETWORK |
| CVE-2021-21137 | 2021-02-09 14:15:17 | MEDIUM (7) | Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page. | NETWORK |
| CVE-2021-21136 | 2021-02-09 14:15:17 | MEDIUM (7) | Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | NETWORK |
| CVE-2021-21135 | 2021-02-09 14:15:17 | MEDIUM (7) | Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | NETWORK |
| CVE-2021-21134 | 2021-02-09 14:15:17 | MEDIUM (7) | Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page. | NETWORK |
| CVE-2021-21133 | 2021-02-09 14:15:16 | MEDIUM (7) | Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a user to download files to bypass navigation restrictions via a crafted HTML page. | NETWORK |
| CVE-2021-21132 | 2021-02-09 14:15:16 | CRITICAL (10) | Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension. | NETWORK |
| CVE-2021-21131 | 2021-02-09 14:15:16 | MEDIUM (7) | Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | NETWORK |
| CVE-2021-21130 | 2021-02-09 14:15:16 | MEDIUM (7) | Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | NETWORK |
| CVE-2021-21129 | 2021-02-09 14:15:16 | MEDIUM (7) | Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | NETWORK |
| CVE-2021-21128 | 2021-02-09 14:15:16 | HIGH (9) | Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | NETWORK |
| CVE-2021-21127 | 2021-02-09 14:15:16 | HIGH (9) | Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension. | NETWORK |
| CVE-2021-21126 | 2021-02-09 14:15:16 | MEDIUM (7) | Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. | NETWORK |
| CVE-2021-21125 | 2021-02-09 14:15:16 | HIGH (8) | Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | NETWORK |
| CVE-2021-21124 | 2021-02-09 14:15:16 | CRITICAL (10) | Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | NETWORK |
| CVE-2021-21123 | 2021-02-09 14:15:16 | MEDIUM (7) | Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | NETWORK |
| CVE-2021-21122 | 2021-02-09 14:15:16 | HIGH (9) | Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | NETWORK |
| CVE-2021-21121 | 2021-02-09 14:15:16 | CRITICAL (10) | Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | NETWORK |
| CVE-2021-21120 | 2021-02-09 14:15:16 | HIGH (9) | Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | NETWORK |
| CVE-2021-21119 | 2021-02-09 14:15:16 | HIGH (9) | Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | NETWORK |
| CVE-2021-21118 | 2021-02-09 14:15:16 | HIGH (9) | Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | NETWORK |
| CVE-2021-1705 | 2021-01-12 20:15:34 | MEDIUM (4) | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | NETWORK |
| CVE-2020-17153 | 2020-12-10 00:15:16 | MEDIUM (4) | Microsoft Edge for Android Spoofing Vulnerability | NETWORK |
| CVE-2020-17058 | 2020-11-11 07:15:17 | HIGH (8) | Microsoft Browser Memory Corruption Vulnerability | NETWORK |
| CVE-2020-16009 | 2020-11-03 03:15:16 | HIGH (9) | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | NETWORK |
| CVE-2020-1569 | 2020-08-17 19:15:21 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge, and then convince a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements by adding specially crafted content that could exploit the vulnerability. In all cases, however, an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically by way of enticement in an email or Instant Messenger message, or by getting them to open an attachment sent through email. The security update addresses the vulnerability by modifying how Microsoft Edge handles objects in memory. | LOCAL |
| CVE-2020-1568 | 2020-08-17 19:15:21 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit the vulnerability, in a web-based attack scenario, an attacker could host a website that contains malicious PDF content. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted PDF content that could exploit the vulnerability. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could trick a user into clicking a link that takes the user to the attacker's site. The security update addresses the vulnerability by modifying how Microsoft Edge PDF Reader handles objects in memory. | NETWORK |
| CVE-2020-1555 | 2020-08-17 19:15:20 | HIGH (9) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge (HTML-based) and then convince a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability. The security update addresses the vulnerability by modifying how the scripting engine handles objects in memory. | NETWORK |
| CVE-2020-1462 | 2020-07-14 23:15:21 | MEDIUM (4) | An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'. | NETWORK |
| CVE-2020-1433 | 2020-07-14 23:15:19 | MEDIUM (7) | An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF Information Disclosure Vulnerability'. | NETWORK |
| CVE-2020-1242 | 2020-06-09 20:15:16 | MEDIUM (5) | An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'. | NETWORK |
| CVE-2020-1219 | 2020-06-09 20:15:15 | HIGH (8) | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'. | NETWORK |
| CVE-2020-1195 | 2020-05-21 23:15:19 | MEDIUM (6) | An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input, aka 'Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability'. | NETWORK |
| CVE-2020-1096 | 2020-05-21 23:15:14 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF Remote Code Execution Vulnerability'. | NETWORK |
| CVE-2020-1059 | 2020-05-21 23:15:12 | MEDIUM (4) | A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka 'Microsoft Edge Spoofing Vulnerability'. | NETWORK |
| CVE-2020-1056 | 2020-05-21 23:15:12 | HIGH (8) | An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability, aka 'Microsoft Edge Elevation of Privilege Vulnerability'. | NETWORK |
| CVE-2020-1037 | 2020-05-21 23:15:12 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. | NETWORK |
| CVE-2020-0969 | 2020-04-15 15:15:18 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. | NETWORK |
| CVE-2020-0878 | 2020-09-11 17:15:14 | MEDIUM (4) | <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft browsers, and then convince a user to view the website. The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. In all cases, however, an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically via an enticement in email or instant message, or by getting them to open an email attachment.</p> <p>The security update addresses the vulnerability by modifying how Microsoft browsers handle objects in memory.</p> | NETWORK |
| CVE-2020-0830 | 2020-03-12 16:15:18 | HIGH (8) | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833, CVE-2020-0848. | NETWORK |
| CVE-2020-0816 | 2020-03-12 16:15:17 | HIGH (9) | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. | NETWORK |
| CVE-2020-0812 | 2020-03-12 16:15:17 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0811. | NETWORK |
| CVE-2020-0811 | 2020-03-12 16:15:17 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0812. | NETWORK |
| CVE-2020-0768 | 2020-03-12 16:15:14 | HIGH (8) | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833, CVE-2020-0848. | NETWORK |
| CVE-2020-0706 | 2020-02-11 22:15:17 | MEDIUM (4) | An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests, aka 'Microsoft Browser Information Disclosure Vulnerability'. | NETWORK |
| CVE-2020-0663 | 2020-02-11 22:15:14 | MEDIUM (4) | An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability, aka 'Microsoft Edge Elevation of Privilege Vulnerability'. | NETWORK |
| CVE-2019-1428 | 2019-11-12 19:15:15 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1429. | NETWORK |
| CVE-2019-1427 | 2019-11-12 19:15:15 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1428, CVE-2019-1429. | NETWORK |
| CVE-2019-1426 | 2019-11-12 19:15:15 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1427, CVE-2019-1428, CVE-2019-1429. | NETWORK |
| CVE-2019-1413 | 2019-11-12 19:15:14 | MEDIUM (4) | A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'. | NETWORK |
| CVE-2019-1366 | 2019-10-10 14:15:18 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1307, CVE-2019-1308, CVE-2019-1335. | NETWORK |
| CVE-2019-1357 | 2019-10-10 14:15:18 | MEDIUM (4) | A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608. | NETWORK |
| CVE-2019-1356 | 2019-10-10 14:15:18 | MEDIUM (7) | An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'. | NETWORK |
| CVE-2019-1335 | 2019-10-10 14:15:17 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1307, CVE-2019-1308, CVE-2019-1366. | NETWORK |
| CVE-2019-1308 | 2019-10-10 14:15:15 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1307, CVE-2019-1335, CVE-2019-1366. | NETWORK |
| CVE-2019-1307 | 2019-10-10 14:15:15 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1308, CVE-2019-1335, CVE-2019-1366. | NETWORK |
| CVE-2019-1300 | 2019-09-11 22:15:19 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, CVE-2019-1217, CVE-2019-1237, CVE-2019-1298. | NETWORK |
| CVE-2019-1299 | 2019-09-11 22:15:19 | MEDIUM (7) | An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'. | NETWORK |
| CVE-2019-1298 | 2019-09-11 22:15:19 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, CVE-2019-1217, CVE-2019-1237, CVE-2019-1300. | NETWORK |
| CVE-2019-1237 | 2019-09-11 22:15:15 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, CVE-2019-1217, CVE-2019-1298, CVE-2019-1300. | NETWORK |
| CVE-2019-1220 | 2019-09-11 22:15:15 | MEDIUM (4) | A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'. | NETWORK |
| CVE-2019-1217 | 2019-09-11 22:15:15 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, CVE-2019-1237, CVE-2019-1298, CVE-2019-1300. | NETWORK |
| CVE-2019-1197 | 2019-08-14 21:15:18 | MEDIUM (4) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge (HTML-based) and then convince a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability. The security update addresses the vulnerability by modifying how the Chakra scripting engine handles objects in memory. | NETWORK |
| CVE-2019-1196 | 2019-08-14 21:15:18 | MEDIUM (4) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge (HTML-based) and then convince a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability. The security update addresses the vulnerability by modifying how the Chakra scripting engine handles objects in memory. | NETWORK |
| CVE-2019-1195 | 2019-08-14 21:15:18 | MEDIUM (4) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge (HTML-based) and then convince a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability. The security update addresses the vulnerability by modifying how the Chakra scripting engine handles objects in memory. | NETWORK |
| CVE-2019-1193 | 2019-08-14 21:15:17 | MEDIUM (6) | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft browsers, and then convince a user to view the website. The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. In all cases, however, an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically via an enticement in email or instant message, or by getting them to open an email attachment. The security update addresses the vulnerability by modifying how Microsoft browsers handle objects in memory. | NETWORK |
| CVE-2019-1192 | 2019-08-14 21:15:17 | MEDIUM (4) | A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An attacker who successfully exploited the vulnerability could force the browser to send data that would otherwise be restricted. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft browsers and then convince a user to view the website. The attacker could also take advantage of compromised websites, and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability. The security update addresses the vulnerability by modifying how affected Microsoft browsers handle different-origin requests. | NETWORK |
| CVE-2019-1141 | 2019-08-14 21:15:14 | MEDIUM (4) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge (HTML-based) and then convince a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability. The security update addresses the vulnerability by modifying how the Chakra scripting engine handles objects in memory. | NETWORK |
| CVE-2019-1140 | 2019-08-14 21:15:14 | HIGH (9) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge (HTML-based) and then convince a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability. The security update addresses the vulnerability by modifying how the Chakra scripting engine handles objects in memory. | NETWORK |
| CVE-2019-1139 | 2019-08-14 21:15:14 | MEDIUM (4) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge (HTML-based) and then convince a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability. The security update addresses the vulnerability by modifying how the Chakra scripting engine handles objects in memory. | NETWORK |
| CVE-2019-1138 | 2019-09-11 22:15:14 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1217, CVE-2019-1237, CVE-2019-1298, CVE-2019-1300. | NETWORK |
| CVE-2019-1131 | 2019-08-14 21:15:14 | MEDIUM (4) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge (HTML-based) and then convince a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability. The security update addresses the vulnerability by modifying how the Chakra scripting engine handles objects in memory. | NETWORK |
| CVE-2019-1107 | 2019-07-15 19:15:20 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1062, CVE-2019-1092, CVE-2019-1103, CVE-2019-1106. | NETWORK |
| CVE-2019-1106 | 2019-07-15 19:15:20 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1062, CVE-2019-1092, CVE-2019-1103, CVE-2019-1107. | NETWORK |
| CVE-2019-1104 | 2019-07-15 19:15:19 | HIGH (8) | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'. | NETWORK |
| CVE-2019-1103 | 2019-07-15 19:15:19 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1062, CVE-2019-1092, CVE-2019-1106, CVE-2019-1107. | NETWORK |
| CVE-2019-1092 | 2019-07-15 19:15:19 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1062, CVE-2019-1103, CVE-2019-1106, CVE-2019-1107. | NETWORK |
| CVE-2019-1081 | 2019-06-12 14:29:04 | MEDIUM (4) | An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, in a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could trick a user into clicking a link that takes the user to the attacker's site. The security update addresses the vulnerability by modifying how Microsoft browsers handle objects in memory. | NETWORK |
| CVE-2019-1062 | 2019-07-15 19:15:17 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1092, CVE-2019-1103, CVE-2019-1106, CVE-2019-1107. | NETWORK |
| CVE-2019-1054 | 2019-06-12 14:29:04 | MEDIUM (5) | A security feature bypass vulnerability exists in Edge that allows for bypassing Mark of the Web Tagging (MOTW). Failing to set the MOTW means that a large number of Microsoft security technologies are bypassed. In a web-based attack scenario, an attacker could host a malicious website that is designed to exploit the security feature bypass. Alternatively, in an email or instant message attack scenario, the attacker could send the targeted user a specially crafted .url file that is designed to exploit the bypass. Additionally, compromised websites or websites that accept or host user-provided content could contain specially crafted content to exploit the security feature bypass. However, in all cases an attacker would have no way to force a user to view attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could entice a user to either click a link that directs the user to the attacker's site or send a malicious attachment. The security update addresses the security feature bypass by correcting how Edge handles MOTW tagging. | NETWORK |
| CVE-2019-1052 | 2019-06-12 14:29:04 | MEDIUM (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0989, CVE-2019-0991, CVE-2019-0992, CVE-2019-0993, CVE-2019-1002, CVE-2019-1003, CVE-2019-1024, CVE-2019-1051. | NETWORK |
| CVE-2019-1051 | 2019-06-12 14:29:04 | MEDIUM (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0989, CVE-2019-0991, CVE-2019-0992, CVE-2019-0993, CVE-2019-1002, CVE-2019-1003, CVE-2019-1024, CVE-2019-1052. | NETWORK |
| CVE-2019-1038 | 2019-06-12 14:29:04 | HIGH (8) | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft browsers, and then convince a user to view the website. The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. In all cases, however, an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically via an enticement in email or instant message, or by getting them to open an email attachment. The security update addresses the vulnerability by modifying how Microsoft browsers handle objects in memory. | NETWORK |
| CVE-2019-1030 | 2019-08-14 21:15:14 | MEDIUM (4) | An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, in a web-based attack scenario, an attacker could host a website in an attempt to exploit the vulnerability. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could trick a user into clicking a link that takes the user to the attacker's site. The update addresses the vulnerability by modifying how Microsoft Edge based on Edge HTML handles objects in memory. | NETWORK |
| CVE-2019-1024 | 2019-06-12 14:29:03 | MEDIUM (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0989, CVE-2019-0991, CVE-2019-0992, CVE-2019-0993, CVE-2019-1002, CVE-2019-1003, CVE-2019-1051, CVE-2019-1052. | NETWORK |
| CVE-2019-1023 | 2019-06-12 14:29:03 | MEDIUM (7) | An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. In a web-based attack scenario, an attacker could host a website in an attempt to exploit the vulnerability. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could trick a user into clicking a link that takes the user to the attacker's site. The security update addresses the vulnerability by changing how the scripting engine handles objects in memory. | NETWORK |
| CVE-2019-1003 | 2019-06-12 14:29:03 | MEDIUM (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0989, CVE-2019-0991, CVE-2019-0992, CVE-2019-0993, CVE-2019-1002, CVE-2019-1024, CVE-2019-1051, CVE-2019-1052. | NETWORK |
| CVE-2019-1002 | 2019-06-12 14:29:02 | MEDIUM (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0989, CVE-2019-0991, CVE-2019-0992, CVE-2019-0993, CVE-2019-1003, CVE-2019-1024, CVE-2019-1051, CVE-2019-1052. | NETWORK |
| CVE-2019-1001 | 2019-07-15 19:15:16 | HIGH (8) | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1004, CVE-2019-1056, CVE-2019-1059. | NETWORK |
| CVE-2019-0993 | 2019-06-12 14:29:02 | MEDIUM (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0989, CVE-2019-0991, CVE-2019-0992, CVE-2019-1002, CVE-2019-1003, CVE-2019-1024, CVE-2019-1051, CVE-2019-1052. | NETWORK |
| CVE-2019-0992 | 2019-06-12 14:29:02 | MEDIUM (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0989, CVE-2019-0991, CVE-2019-0993, CVE-2019-1002, CVE-2019-1003, CVE-2019-1024, CVE-2019-1051, CVE-2019-1052. | NETWORK |
| CVE-2019-0991 | 2019-06-12 14:29:02 | MEDIUM (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0989, CVE-2019-0992, CVE-2019-0993, CVE-2019-1002, CVE-2019-1003, CVE-2019-1024, CVE-2019-1051, CVE-2019-1052. | NETWORK |
| CVE-2019-0990 | 2019-06-12 14:29:02 | MEDIUM (7) | An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1023. | NETWORK |
| CVE-2019-0989 | 2019-06-12 14:29:02 | MEDIUM (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0991, CVE-2019-0992, CVE-2019-0993, CVE-2019-1002, CVE-2019-1003, CVE-2019-1024, CVE-2019-1051, CVE-2019-1052. | NETWORK |
| CVE-2019-0940 | 2019-05-16 19:29:04 | HIGH (8) | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'. | NETWORK |
| CVE-2019-0938 | 2019-05-16 19:29:04 | MEDIUM (7) | An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka 'Microsoft Edge Elevation of Privilege Vulnerability'. | NETWORK |
| CVE-2019-0937 | 2019-05-16 19:29:04 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0912, CVE-2019-0913, CVE-2019-0914, CVE-2019-0915, CVE-2019-0916, CVE-2019-0917, CVE-2019-0922, CVE-2019-0923, CVE-2019-0924, CVE-2019-0925, CVE-2019-0927, CVE-2019-0933. | NETWORK |
| CVE-2019-0933 | 2019-05-16 19:29:04 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0912, CVE-2019-0913, CVE-2019-0914, CVE-2019-0915, CVE-2019-0916, CVE-2019-0917, CVE-2019-0922, CVE-2019-0923, CVE-2019-0924, CVE-2019-0925, CVE-2019-0927, CVE-2019-0937. | NETWORK |
| CVE-2019-0927 | 2019-05-16 19:29:03 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0912, CVE-2019-0913, CVE-2019-0914, CVE-2019-0915, CVE-2019-0916, CVE-2019-0917, CVE-2019-0922, CVE-2019-0923, CVE-2019-0924, CVE-2019-0925, CVE-2019-0933, CVE-2019-0937. | NETWORK |
| CVE-2019-0926 | 2019-05-16 19:29:03 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. | NETWORK |
| CVE-2019-0925 | 2019-05-16 19:29:03 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0912, CVE-2019-0913, CVE-2019-0914, CVE-2019-0915, CVE-2019-0916, CVE-2019-0917, CVE-2019-0922, CVE-2019-0923, CVE-2019-0924, CVE-2019-0927, CVE-2019-0933, CVE-2019-0937. | NETWORK |
| CVE-2019-0924 | 2019-05-16 19:29:03 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0912, CVE-2019-0913, CVE-2019-0914, CVE-2019-0915, CVE-2019-0916, CVE-2019-0917, CVE-2019-0922, CVE-2019-0923, CVE-2019-0925, CVE-2019-0927, CVE-2019-0933, CVE-2019-0937. | NETWORK |
| CVE-2019-0923 | 2019-05-16 19:29:03 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0912, CVE-2019-0913, CVE-2019-0914, CVE-2019-0915, CVE-2019-0916, CVE-2019-0917, CVE-2019-0922, CVE-2019-0924, CVE-2019-0925, CVE-2019-0927, CVE-2019-0933, CVE-2019-0937. | NETWORK |
| CVE-2019-0922 | 2019-05-16 19:29:03 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0912, CVE-2019-0913, CVE-2019-0914, CVE-2019-0915, CVE-2019-0916, CVE-2019-0917, CVE-2019-0923, CVE-2019-0924, CVE-2019-0925, CVE-2019-0927, CVE-2019-0933, CVE-2019-0937. | NETWORK |
| CVE-2019-0917 | 2019-05-16 19:29:03 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0912, CVE-2019-0913, CVE-2019-0914, CVE-2019-0915, CVE-2019-0916, CVE-2019-0922, CVE-2019-0923, CVE-2019-0924, CVE-2019-0925, CVE-2019-0927, CVE-2019-0933, CVE-2019-0937. | NETWORK |
| CVE-2019-0916 | 2019-05-16 19:29:03 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0912, CVE-2019-0913, CVE-2019-0914, CVE-2019-0915, CVE-2019-0917, CVE-2019-0922, CVE-2019-0923, CVE-2019-0924, CVE-2019-0925, CVE-2019-0927, CVE-2019-0933, CVE-2019-0937. | NETWORK |
| CVE-2019-0915 | 2019-05-16 19:29:03 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0912, CVE-2019-0913, CVE-2019-0914, CVE-2019-0916, CVE-2019-0917, CVE-2019-0922, CVE-2019-0923, CVE-2019-0924, CVE-2019-0925, CVE-2019-0927, CVE-2019-0933, CVE-2019-0937. | NETWORK |
| CVE-2019-0914 | 2019-05-16 19:29:03 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0912, CVE-2019-0913, CVE-2019-0915, CVE-2019-0916, CVE-2019-0917, CVE-2019-0922, CVE-2019-0923, CVE-2019-0924, CVE-2019-0925, CVE-2019-0927, CVE-2019-0933, CVE-2019-0937. | NETWORK |
| CVE-2019-0913 | 2019-05-16 19:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0912, CVE-2019-0914, CVE-2019-0915, CVE-2019-0916, CVE-2019-0917, CVE-2019-0922, CVE-2019-0923, CVE-2019-0924, CVE-2019-0925, CVE-2019-0927, CVE-2019-0933, CVE-2019-0937. | NETWORK |
| CVE-2019-0912 | 2019-05-16 19:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0913, CVE-2019-0914, CVE-2019-0915, CVE-2019-0916, CVE-2019-0917, CVE-2019-0922, CVE-2019-0923, CVE-2019-0924, CVE-2019-0925, CVE-2019-0927, CVE-2019-0933, CVE-2019-0937. | NETWORK |
| CVE-2019-0911 | 2019-05-16 19:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0884, CVE-2019-0918. | NETWORK |
| CVE-2019-0884 | 2019-05-16 19:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0911, CVE-2019-0918. | NETWORK |
| CVE-2019-0861 | 2019-04-09 21:29:03 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0810, CVE-2019-0812, CVE-2019-0829, CVE-2019-0860. | NETWORK |
| CVE-2019-0860 | 2019-04-09 21:29:03 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0810, CVE-2019-0812, CVE-2019-0829, CVE-2019-0861. | NETWORK |
| CVE-2019-0833 | 2019-04-09 21:29:02 | MEDIUM (4) | An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka 'Microsoft Edge Information Disclosure Vulnerability'. | NETWORK |
| CVE-2019-0829 | 2019-04-09 21:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0810, CVE-2019-0812, CVE-2019-0860, CVE-2019-0861. | NETWORK |
| CVE-2019-0812 | 2019-04-09 21:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0810, CVE-2019-0829, CVE-2019-0860, CVE-2019-0861. | NETWORK |
| CVE-2019-0810 | 2019-04-09 21:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0812, CVE-2019-0829, CVE-2019-0860, CVE-2019-0861. | NETWORK |
| CVE-2019-0806 | 2019-04-09 21:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0810, CVE-2019-0812, CVE-2019-0829, CVE-2019-0860, CVE-2019-0861. | NETWORK |
| CVE-2019-0780 | 2019-04-09 03:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'. | NETWORK |
| CVE-2019-0779 | 2019-04-09 03:29:01 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. | NETWORK |
| CVE-2019-0773 | 2019-04-09 03:29:00 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0639, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0783. | NETWORK |
| CVE-2019-0771 | 2019-04-09 03:29:00 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0639, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0773, CVE-2019-0783. | NETWORK |
| CVE-2019-0770 | 2019-04-09 03:29:00 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0639, CVE-2019-0680, CVE-2019-0769, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783. | NETWORK |
| CVE-2019-0769 | 2019-04-09 02:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0639, CVE-2019-0680, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783. | NETWORK |
| CVE-2019-0764 | 2019-04-09 21:29:01 | MEDIUM (4) | A tampering vulnerability exists when Microsoft browsers do not properly validate input under specific conditions, aka 'Microsoft Browsers Tampering Vulnerability'. | NETWORK |
| CVE-2019-0762 | 2019-04-09 02:29:01 | MEDIUM (4) | A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'. | NETWORK |
| CVE-2019-0746 | 2019-04-09 00:29:01 | MEDIUM (4) | An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'. | NETWORK |
| CVE-2019-0739 | 2019-04-09 21:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0752, CVE-2019-0753, CVE-2019-0862. | NETWORK |
| CVE-2019-0678 | 2019-04-09 00:29:00 | MEDIUM (4) | An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability, aka 'Microsoft Edge Elevation of Privilege Vulnerability'. | NETWORK |
| CVE-2019-0658 | 2019-03-05 23:29:02 | MEDIUM (4) | An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0648. | NETWORK |
| CVE-2019-0655 | 2019-03-05 23:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0644, CVE-2019-0651, CVE-2019-0652. | NETWORK |
| CVE-2019-0654 | 2019-03-05 23:29:02 | MEDIUM (4) | A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'. | NETWORK |
| CVE-2019-0652 | 2019-03-05 23:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0644, CVE-2019-0651, CVE-2019-0655. | NETWORK |
| CVE-2019-0651 | 2019-03-05 23:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0644, CVE-2019-0652, CVE-2019-0655. | NETWORK |
| CVE-2019-0650 | 2019-03-05 23:29:02 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0634, CVE-2019-0645. | NETWORK |
| CVE-2019-0649 | 2019-03-05 23:29:02 | MEDIUM (7) | A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileged Vulnerability'. | NETWORK |
| CVE-2019-0645 | 2019-03-05 23:29:02 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0634, CVE-2019-0650. | NETWORK |
| CVE-2019-0644 | 2019-03-05 23:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655. | NETWORK |
| CVE-2019-0643 | 2019-03-05 23:29:02 | MEDIUM (4) | An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'. | NETWORK |
| CVE-2019-0642 | 2019-03-05 23:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0644, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655. | NETWORK |
| CVE-2019-0641 | 2019-03-05 23:29:02 | MEDIUM (4) | A security feature bypass vulnerability exists in Microsoft Edge handles whitelisting, aka 'Microsoft Edge Security Feature Bypass Vulnerability'. | NETWORK |
| CVE-2019-0640 | 2019-03-05 23:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0642, CVE-2019-0644, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655. | NETWORK |
| CVE-2019-0634 | 2019-03-05 23:29:01 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0645, CVE-2019-0650. | NETWORK |
| CVE-2019-0612 | 2019-04-08 23:29:00 | LOW (3) | A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By itself, this bypass vulnerability does not allow arbitrary code execution, aka 'Microsoft Edge Security Feature Bypass Vulnerability'. | NETWORK |
| CVE-2019-0611 | 2019-04-08 23:29:00 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0592. | NETWORK |
| CVE-2019-0610 | 2019-03-05 23:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0640, CVE-2019-0642, CVE-2019-0644, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655. | NETWORK |
| CVE-2019-0609 | 2019-04-08 23:29:00 | HIGH (8) | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0639, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783. | NETWORK |
| CVE-2019-0608 | 2019-10-10 14:15:14 | MEDIUM (4) | A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357. | NETWORK |
| CVE-2019-0607 | 2019-03-05 23:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0644, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655. | NETWORK |
| CVE-2019-0605 | 2019-03-05 23:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0593, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0644, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655. | NETWORK |
| CVE-2019-0593 | 2019-03-05 23:29:00 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0591, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0644, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655. | NETWORK |
| CVE-2019-0592 | 2019-04-08 23:29:00 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0611. | NETWORK |
| CVE-2019-0591 | 2019-03-05 23:29:00 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0590, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0644, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655. | NETWORK |
| CVE-2019-0590 | 2019-03-05 23:29:00 | HIGH (8) | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0644, CVE-2019-0651, CVE-2019-0652, CVE-2019-0655. | NETWORK |
| CVE-2019-0568 | 2019-01-08 21:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2019-0539, CVE-2019-0567. | NETWORK |
| CVE-2019-0567 | 2019-01-08 21:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2019-0539, CVE-2019-0568. | NETWORK |
| CVE-2019-0566 | 2019-01-08 21:29:01 | MEDIUM (7) | An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. | NETWORK |
| CVE-2019-0565 | 2019-01-08 21:29:01 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. | NETWORK |
| CVE-2019-0539 | 2019-01-08 21:29:00 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2019-0567, CVE-2019-0568. | NETWORK |
| CVE-2018-8629 | 2018-12-12 00:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8583, CVE-2018-8617, CVE-2018-8618, CVE-2018-8624. | NETWORK |
| CVE-2018-8624 | 2018-12-12 00:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8583, CVE-2018-8617, CVE-2018-8618, CVE-2018-8629. | NETWORK |
| CVE-2018-8618 | 2018-12-12 00:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8583, CVE-2018-8617, CVE-2018-8624, CVE-2018-8629. | NETWORK |
| CVE-2018-8617 | 2018-12-12 00:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8583, CVE-2018-8618, CVE-2018-8624, CVE-2018-8629. | NETWORK |
| CVE-2018-8588 | 2018-11-14 01:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8541, CVE-2018-8542, CVE-2018-8543, CVE-2018-8551, CVE-2018-8555, CVE-2018-8556, CVE-2018-8557. | NETWORK |
| CVE-2018-8583 | 2018-12-12 00:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8617, CVE-2018-8618, CVE-2018-8624, CVE-2018-8629. | NETWORK |
| CVE-2018-8567 | 2018-11-14 01:29:02 | MEDIUM (6) | An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. | NETWORK |
| CVE-2018-8564 | 2018-11-14 01:29:01 | MEDIUM (4) | A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. | NETWORK |
| CVE-2018-8557 | 2018-11-14 01:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8541, CVE-2018-8542, CVE-2018-8543, CVE-2018-8551, CVE-2018-8555, CVE-2018-8556, CVE-2018-8588. | NETWORK |
| CVE-2018-8556 | 2018-11-14 01:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8541, CVE-2018-8542, CVE-2018-8543, CVE-2018-8551, CVE-2018-8555, CVE-2018-8557, CVE-2018-8588. | NETWORK |
| CVE-2018-8555 | 2018-11-14 01:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8541, CVE-2018-8542, CVE-2018-8543, CVE-2018-8551, CVE-2018-8556, CVE-2018-8557, CVE-2018-8588. | NETWORK |
| CVE-2018-8551 | 2018-11-14 01:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8541, CVE-2018-8542, CVE-2018-8543, CVE-2018-8555, CVE-2018-8556, CVE-2018-8557, CVE-2018-8588. | NETWORK |
| CVE-2018-8545 | 2018-11-14 01:29:01 | MEDIUM (4) | An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. | NETWORK |
| CVE-2018-8543 | 2018-11-14 01:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8541, CVE-2018-8542, CVE-2018-8551, CVE-2018-8555, CVE-2018-8556, CVE-2018-8557, CVE-2018-8588. | NETWORK |
| CVE-2018-8542 | 2018-11-14 01:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8541, CVE-2018-8543, CVE-2018-8551, CVE-2018-8555, CVE-2018-8556, CVE-2018-8557, CVE-2018-8588. | NETWORK |
| CVE-2018-8541 | 2018-11-14 01:29:01 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8542, CVE-2018-8543, CVE-2018-8551, CVE-2018-8555, CVE-2018-8556, CVE-2018-8557, CVE-2018-8588. | NETWORK |
| CVE-2018-8530 | 2018-10-10 13:29:06 | MEDIUM (4) | A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8512. | NETWORK |
| CVE-2018-8513 | 2018-10-10 13:29:06 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8503, CVE-2018-8505, CVE-2018-8510, CVE-2018-8511. | NETWORK |
| CVE-2018-8512 | 2018-10-10 13:29:06 | MEDIUM (6) | A security feature bypass vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8530. | NETWORK |
| CVE-2018-8511 | 2018-10-10 13:29:06 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8503, CVE-2018-8505, CVE-2018-8510, CVE-2018-8513. | NETWORK |
| CVE-2018-8510 | 2018-10-10 13:29:05 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8503, CVE-2018-8505, CVE-2018-8511, CVE-2018-8513. | NETWORK |
| CVE-2018-8509 | 2018-10-10 13:29:05 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8473. | NETWORK |
| CVE-2018-8505 | 2018-10-10 13:29:05 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8503, CVE-2018-8510, CVE-2018-8511, CVE-2018-8513. | NETWORK |
| CVE-2018-8503 | 2018-10-10 13:29:05 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8505, CVE-2018-8510, CVE-2018-8511, CVE-2018-8513. | NETWORK |
| CVE-2018-8473 | 2018-10-10 13:29:03 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8509. | NETWORK |
| CVE-2018-8469 | 2018-09-13 00:29:07 | MEDIUM (4) | An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8463. | NETWORK |
| CVE-2018-8467 | 2018-09-13 00:29:07 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8367, CVE-2018-8465, CVE-2018-8466. | NETWORK |
| CVE-2018-8466 | 2018-09-13 00:29:07 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8367, CVE-2018-8465, CVE-2018-8467. | NETWORK |
| CVE-2018-8465 | 2018-09-13 00:29:06 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8367, CVE-2018-8466, CVE-2018-8467. | NETWORK |
| CVE-2018-8464 | 2018-09-13 00:29:06 | HIGH (9) | An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge PDF Remote Code Execution Vulnerability." This affects Microsoft Edge. | NETWORK |
| CVE-2018-8463 | 2018-09-13 00:29:06 | MEDIUM (4) | An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8469. | NETWORK |
| CVE-2018-8459 | 2018-09-13 00:29:06 | HIGH (8) | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8354, CVE-2018-8391, CVE-2018-8456, CVE-2018-8457. | NETWORK |
| CVE-2018-8457 | 2018-09-13 00:29:06 | HIGH (8) | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-8354, CVE-2018-8391, CVE-2018-8456, CVE-2018-8459. | NETWORK |
| CVE-2018-8456 | 2018-09-13 00:29:06 | HIGH (8) | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8354, CVE-2018-8391, CVE-2018-8457, CVE-2018-8459. | NETWORK |
| CVE-2018-8452 | 2018-09-13 00:29:05 | MEDIUM (4) | An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aka "Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. | NETWORK |
| CVE-2018-8425 | 2018-09-13 00:29:03 | MEDIUM (4) | A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. | NETWORK |
| CVE-2018-8403 | 2018-08-15 17:29:10 | HIGH (8) | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka "Microsoft Browser Memory Corruption Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10. | NETWORK |
| CVE-2018-8390 | 2018-08-15 17:29:09 | HIGH (8) | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8389. | NETWORK |
| CVE-2018-8388 | 2018-08-15 17:29:08 | MEDIUM (4) | A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8383. | NETWORK |
| CVE-2018-8387 | 2018-08-15 17:29:08 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8377. | NETWORK |
| CVE-2018-8385 | 2018-08-15 17:29:08 | HIGH (8) | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8389, CVE-2018-8390. | NETWORK |
| CVE-2018-8383 | 2018-08-15 17:29:08 | MEDIUM (4) | A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8388. | NETWORK |
| CVE-2018-8381 | 2018-08-15 17:29:08 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8266, CVE-2018-8380, CVE-2018-8384. | NETWORK |
| CVE-2018-8380 | 2018-08-15 17:29:08 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8266, CVE-2018-8381, CVE-2018-8384. | NETWORK |
| CVE-2018-8377 | 2018-08-15 17:29:07 | HIGH (8) | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8387. | NETWORK |
| CVE-2018-8372 | 2018-08-15 17:29:07 | HIGH (8) | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8373, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390. | NETWORK |
| CVE-2018-8370 | 2018-08-15 17:29:06 | MEDIUM (4) | A information disclosure vulnerability exists when WebAudio Library improperly handles audio requests, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. | NETWORK |
| CVE-2018-8367 | 2018-09-13 00:29:02 | HIGH (8) | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8465, CVE-2018-8466, CVE-2018-8467. | NETWORK |
| CVE-2018-8366 | 2018-09-13 00:29:01 | LOW (3) | An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. | NETWORK |
| CVE-2018-8358 | 2018-08-15 17:29:06 | MEDIUM (4) | A security feature bypass vulnerability exists when Microsoft Edge improperly handles redirect requests, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge. | NETWORK |
| CVE-2018-8357 | 2018-08-15 17:29:06 | MEDIUM (5) | An elevation of privilege vulnerability exists in Microsoft browsers allowing sandbox escape, aka "Microsoft Browser Elevation of Privilege Vulnerability." This affects Internet Explorer 11, Microsoft Edge. | NETWORK |
Showing the 500 most recent of 979 tracked CVEs.
Why keeping Microsoft Edge patched matters
Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Microsoft Edge release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.
How Lavawall® patches Microsoft Edge
Lavawall® watches Microsoft Edge releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Microsoft Edge, one policy to bring them current, and timestamped evidence for audits.
Frequently asked questions
Lavawall tracks Microsoft Edge at version 151.0.4129.59 (last checked 2026-08-10). New releases are monitored continuously and can be deployed automatically across your fleet.
Lavawall continuously monitors Microsoft Edge for newly disclosed CVEs and remediates them automatically as they appear.
Deploy the Lavawall® agent and Microsoft Edge updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.
Lavawall® monitors releases and CVEs for Microsoft Edge through public information and proprietary statistical analysis, and can patch it automatically across your fleet.