Microsoft Chakracore vulnerabilities
206 known vulnerabilities affecting microsoft/chakracore.
Total CVEs
206
CISA KEV
3
actively exploited
Public exploits
34
Exploited in wild
6
Severity breakdown
CRITICAL2HIGH179MEDIUM25
Vulnerabilities
Page 10 of 11
CVE-2021-42279P3HIGHCVSS 7.5vN/A2021-11-10
CVE-2021-42279 [HIGH] CWE-787 CVE-2021-42279: Chakra Scripting Engine Memory Corruption Vulnerability
Chakra Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2020-17131P3HIGHCVSS 7.5fixed in 1.11.0fixed in publication2020-12-10
CVE-2020-17131 [HIGH] CWE-787 CVE-2020-17131: Chakra Scripting Engine Memory Corruption Vulnerability
Chakra Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2020-17054P3HIGHCVSS 7.5≥ 1.11.0, < 1.11.23fixed in publication2020-11-11
CVE-2020-17054 [HIGH] CWE-787 CVE-2020-17054: Chakra Scripting Engine Memory Corruption Vulnerability
Chakra Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2020-23315P3HIGHCVSS 7.5v1.12.0.02022-01-20
CVE-2020-23315 [HIGH] CVE-2020-23315: There is an ASSERTION (pFuncBody->GetYieldRegister() == oldYieldRegister) failed in Js::DebugContext
There is an ASSERTION (pFuncBody->GetYieldRegister() == oldYieldRegister) failed in Js::DebugContext::RundownSourcesAndReparse in ChakraCore version 1.12.0.0-beta.
nvd
CVE-2019-0658P3MEDIUMCVSS 6.5fixed in 1.11.62019-03-05
CVE-2019-0658 [MEDIUM] CVE-2019-0658: An information disclosure vulnerability exists when the scripting engine does not properly handle ob
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0648.
nvd
CVE-2019-1023P3MEDIUMCVSS 6.5fixed in 1.11.10fixed in publication2019-06-12
CVE-2019-1023 [MEDIUM] CWE-200 CVE-2019-1023: An information disclosure vulnerability exists when the scripting engine does not properly handle ob
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
In a web-based attack scenario, an attacker could host a website in an attempt to exploit the v
nvd
CVE-2018-8276P3MEDIUMCVSS 6.5vChakraCore2018-07-11
CVE-2018-8276 [MEDIUM] CVE-2018-8276: A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows
A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows Control Flow Guard (CFG) to be bypassed, aka "Scripting Engine Security Feature Bypass Vulnerability." This affects Microsoft Edge, ChakraCore.
nvd
CVE-2019-0746P4MEDIUMCVSS 6.5vWindows 10 for 32-bit Systems2019-04-09
CVE-2019-0746 [MEDIUM] CVE-2019-0746: An information disclosure vulnerability exists when the scripting engine does not properly handle ob
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'.
nvd
CVE-2017-11919P4MEDIUMCVSS 5.3fixed in 1.7.52017-12-12
CVE-2017-11919 [MEDIUM] CVE-2017-11919: ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016, and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromi
nvd
CVE-2018-0800P4MEDIUMCVSS 5.3≤ 1.7.62018-01-04
CVE-2018-0800 [MEDIUM] CVE-2018-0800: Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further comp
Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0767 and CVE-2018-0780.
nvd
CVE-2019-1051P4MEDIUMCVSS 4.2fixed in 1.11.10fixed in publication2019-06-12
CVE-2019-1051 [MEDIUM] CWE-787 CVE-2019-1051: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-0991P4MEDIUMCVSS 4.2fixed in 1.11.10fixed in publication2019-06-12
CVE-2019-0991 [MEDIUM] CWE-787 CVE-2019-0991: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-0993P4MEDIUMCVSS 4.2fixed in 1.11.10fixed in publication2019-06-12
CVE-2019-0993 [MEDIUM] CWE-787 CVE-2019-0993: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-1003P4MEDIUMCVSS 4.2fixed in 1.11.10fixed in publication2019-06-12
CVE-2019-1003 [MEDIUM] CWE-787 CVE-2019-1003: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-1052P4MEDIUMCVSS 4.2fixed in 1.11.10fixed in publication2019-06-12
CVE-2019-1052 [MEDIUM] CWE-787 CVE-2019-1052: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-0989P4MEDIUMCVSS 4.2fixed in 1.11.10fixed in publication2019-06-12
CVE-2019-0989 [MEDIUM] CWE-787 CVE-2019-0989: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-1024P4MEDIUMCVSS 4.2fixed in 1.11.10fixed in publication2019-06-12
CVE-2019-1024 [MEDIUM] CWE-787 CVE-2019-1024: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-1139P4MEDIUMCVSS 4.2fixed in publication2019-08-14
CVE-2019-1139 [MEDIUM] CWE-787 CVE-2019-1139: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-1196P4MEDIUMCVSS 4.2fixed in publication2019-08-14
CVE-2019-1196 [MEDIUM] CWE-787 CVE-2019-1196: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-1197P4MEDIUMCVSS 4.2fixed in publication2019-08-14
CVE-2019-1197 [MEDIUM] CWE-787 CVE-2019-1197: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd