CVE-2016-7208Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Edge ON Windows 10 Version 1511 FOR 32-bit Systems

Severity
8.8HIGHNVD
NVD7.5
EPSS
15.2%
top 5.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateMay 14

Description

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

🔴Vulnerability Details

18
GHSA
ChakraCore RCE Vulnerability2022-05-14
GHSA
ChakraCore RCE Vulnerability2022-05-14
OSV
ChakraCore RCE Vulnerability2022-05-14
GHSA
ChakraCore RCE Vulnerability2022-05-14
GHSA
ChakraCore RCE Vulnerability2022-05-14

📋Vendor Advisories

2
Microsoft
Scripting Engine Memory Corruption Vulnerability2016-11-08
Red Hat
Mozilla: Firefox allows for control characters to be set in cookie names (MFSA 2016-04)2016-01-26