cbcvebase.

Microsoft Chakracore vulnerabilities

206 known vulnerabilities affecting microsoft/chakracore.

Total CVEs
206
CISA KEV
3
actively exploited
Public exploits
34
Exploited in wild
6
Severity breakdown
CRITICAL2HIGH179MEDIUM25

Vulnerabilities

Page 2 of 11
CVE-2018-8353P2HIGHCVSS 7.5PoCvChakraCore2018-08-15
CVE-2018-8353 [HIGH] CWE-416 CVE-2018-8353: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-
nvd
CVE-2018-0933P2HIGHCVSS 7.5PoCfixed in 1.8.22018-03-14
CVE-2018-0933 [HIGH] CVE-2018-0933: ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows rem ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0872, CVE-2018-0873, CVE-2018-0874, CVE-2018-0930, CVE-2018-0931, CVE-2018-093
nvd
CVE-2018-0934P2HIGHCVSS 7.5PoCfixed in 1.8.22018-03-14
CVE-2018-0934 [HIGH] CVE-2018-0934: ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows rem ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0872, CVE-2018-0873, CVE-2018-0874, CVE-2018-0930, CVE-2018-0931, CVE-2018-093
nvd
CVE-2017-11811P2HIGHCVSS 7.5PoCfixed in 1.7.32017-10-13
CVE-2017-11811 [HIGH] CVE-2017-11811: ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 201 ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-
nvd
CVE-2018-8229P2HIGHCVSS 7.5PoC≤ 1.8.42018-06-14
CVE-2018-8229 [HIGH] CVE-2018-8229: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8227.
nvd
CVE-2018-8291P2HIGHCVSS 7.5PoCfixed in 1.10.12018-07-11
CVE-2018-8291 [HIGH] CVE-2018-8291: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8288, CVE-2018-8296, CVE-2018-8298.
nvd
CVE-2018-8288P2HIGHCVSS 7.5PoCfixed in 1.10.12018-07-11
CVE-2018-8288 [HIGH] CVE-2018-8288: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287, CVE-2018-8291, CVE-2018-8296, CVE-2018-8298.
nvd
CVE-2017-11799P2HIGHCVSS 7.5PoC≤ 1.7.22017-10-13
CVE-2017-11799 [HIGH] CVE-2017-11799: ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 201 ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-
nvd
CVE-2018-8466P2HIGHCVSS 7.5PoC≤ 1.10.12018-09-13
CVE-2018-8466 [HIGH] CVE-2018-8466: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8367, CVE-2018-8465, CVE-2018-8467.
nvd
CVE-2017-11918P2HIGHCVSS 7.5PoCfixed in 1.7.52017-12-12
CVE-2017-11918 [HIGH] CVE-2017-11918: ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 al ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-
nvd
CVE-2017-11914P2HIGHCVSS 7.5PoCfixed in 1.7.52017-12-12
CVE-2017-11914 [HIGH] CVE-2017-11914: ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows a ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-1
nvd
CVE-2018-8145P2HIGHCVSS 7.5PoC≤ 1.8.32018-05-09
CVE-2018-8145 [HIGH] CVE-2018-8145: An information disclosure vulnerability exists when Chakra improperly discloses the contents of its An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE
nvd
CVE-2018-8139P2HIGHCVSS 7.5PoC≤ 1.8.32018-05-09
CVE-2018-8139 [HIGH] CVE-2018-8139: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-201
nvd
CVE-2018-0980P2HIGHCVSS 7.5PoCfixed in 1.8.32018-04-12
CVE-2018-0980 [HIGH] CVE-2018-0980: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0979, CVE-2018-0990, CVE-2018-0993, CVE-2018-0994, CVE-2018-0995, CVE-2018-1019.
nvd
CVE-2018-0946P2HIGHCVSS 7.5PoC≤ 1.8.32018-05-09
CVE-2018-0946 [HIGH] CVE-2018-0946: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0945, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8114, CVE-201
nvd
CVE-2018-0767P3MEDIUMCVSS 5.3PoCfixed in 1.7.62018-01-04
CVE-2018-0767 [MEDIUM] CWE-125 CVE-2018-0767: Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an att Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0780 and CVE-2018-0800.
nvd
CVE-2018-0780P3MEDIUMCVSS 5.3PoCfixed in 1.7.62018-01-04
CVE-2018-0780 [MEDIUM] CVE-2018-0780: Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0767 and CVE-2018-0800.
nvd
CVE-2017-11812P3HIGHCVSS 7.5≤ 1.7.22017-10-13
CVE-2017-11812 [HIGH] CVE-2017-11812: ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allo ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-1
nvd
CVE-2018-8500P3CRITICALCVSS 9.8vChakraCore2018-10-10
CVE-2018-8500 [CRITICAL] CWE-787 CVE-2018-8500: A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore.
nvd
CVE-2017-8658P3CRITICALCVSS 9.8≤ 1.7.02017-08-11
CVE-2017-8658 [CRITICAL] CWE-119 CVE-2017-8658: A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders wh A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".
nvd