CVE-2018-8564Microsoft Edge vulnerability

4 documents4 sources
Severity
4.3MEDIUMNVD
EPSS
6.1%
top 9.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 14
Latest updateMay 13

Description

A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

CVEListV5microsoft/microsoft_edge17 versions+16

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h8w6-2pq6-m397: A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability2022-05-13
CVEList
CVE-2018-8564: A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability2018-11-14

📋Vendor Advisories

1
Microsoft
Microsoft Edge Spoofing Vulnerability2018-11-13
CVE-2018-8564 — Microsoft Edge vulnerability | cvebase