Microsoft Chakracore vulnerabilities
206 known vulnerabilities affecting microsoft/chakracore.
Total CVEs
206
CISA KEV
3
actively exploited
Public exploits
34
Exploited in wild
5
Severity breakdown
CRITICAL2HIGH179MEDIUM25
Vulnerabilities
Page 3 of 11
CVE-2019-1217HIGHCVSS 7.5fixed in 1.11.132019-09-11
CVE-2019-1217 [HIGH] CVE-2019-1217: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, CVE-2019-1237, CVE-2019-1298, CVE-2019-1300.
nvd
CVE-2019-1237HIGHCVSS 7.5fixed in 1.11.132019-09-11
CVE-2019-1237 [HIGH] CVE-2019-1237: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, CVE-2019-1217, CVE-2019-1298, CVE-2019-1300.
nvd
CVE-2019-1138HIGHCVSS 7.5fixed in 1.11.13vunspecified2019-09-11
CVE-2019-1138 [HIGH] CWE-787 CVE-2019-1138: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1217, CVE-2019-1237, CVE-2019-1298, CVE-2019-1300.
nvd
CVE-2019-1298HIGHCVSS 7.5fixed in 1.11.132019-09-11
CVE-2019-1298 [HIGH] CVE-2019-1298: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, CVE-2019-1217, CVE-2019-1237, CVE-2019-1300.
nvd
CVE-2019-1300HIGHCVSS 7.5fixed in 1.11.132019-09-11
CVE-2019-1300 [HIGH] CVE-2019-1300: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, CVE-2019-1217, CVE-2019-1237, CVE-2019-1298.
nvd
CVE-2019-1140HIGHCVSS 8.8fixed in publication2019-08-14
CVE-2019-1140 [HIGH] CWE-787 CVE-2019-1140: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the s
nvd
CVE-2019-1139MEDIUMCVSS 4.2fixed in publication2019-08-14
CVE-2019-1139 [MEDIUM] CWE-787 CVE-2019-1139: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-1196MEDIUMCVSS 4.2fixed in publication2019-08-14
CVE-2019-1196 [MEDIUM] CWE-787 CVE-2019-1196: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-1195MEDIUMCVSS 4.2fixed in publication2019-08-14
CVE-2019-1195 [MEDIUM] CWE-787 CVE-2019-1195: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-1131MEDIUMCVSS 4.2fixed in publication2019-08-14
CVE-2019-1131 [MEDIUM] CWE-787 CVE-2019-1131: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-1197MEDIUMCVSS 4.2fixed in publication2019-08-14
CVE-2019-1197 [MEDIUM] CWE-787 CVE-2019-1197: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-1141MEDIUMCVSS 4.2fixed in publication2019-08-14
CVE-2019-1141 [MEDIUM] CWE-787 CVE-2019-1141: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2019-1001HIGHCVSS 7.5fixed in 1.11.112019-07-15
CVE-2019-1001 [HIGH] CWE-787 CVE-2019-1001: A remote code execution vulnerability exists in the way the scripting engine handles objects in memo
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1004, CVE-2019-1056, CVE-2019-1059.
nvd
CVE-2019-1107HIGHCVSS 7.5fixed in 1.11.112019-07-15
CVE-2019-1107 [HIGH] CVE-2019-1107: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1062, CVE-2019-1092, CVE-2019-1103, CVE-2019-1106.
nvd
CVE-2019-1092HIGHCVSS 7.5fixed in 1.11.112019-07-15
CVE-2019-1092 [HIGH] CVE-2019-1092: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1062, CVE-2019-1103, CVE-2019-1106, CVE-2019-1107.
nvd
CVE-2019-1062HIGHCVSS 7.5fixed in 1.11.11vunspecified2019-07-15
CVE-2019-1062 [HIGH] CWE-787 CVE-2019-1062: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1092, CVE-2019-1103, CVE-2019-1106, CVE-2019-1107.
nvd
CVE-2019-1103HIGHCVSS 7.5fixed in 1.11.112019-07-15
CVE-2019-1103 [HIGH] CVE-2019-1103: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1062, CVE-2019-1092, CVE-2019-1106, CVE-2019-1107.
nvd
CVE-2019-1106HIGHCVSS 7.5fixed in 1.11.112019-07-15
CVE-2019-1106 [HIGH] CVE-2019-1106: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1062, CVE-2019-1092, CVE-2019-1103, CVE-2019-1107.
nvd
CVE-2019-1023MEDIUMCVSS 6.5fixed in 1.11.10fixed in publication2019-06-12
CVE-2019-1023 [MEDIUM] CWE-200 CVE-2019-1023: An information disclosure vulnerability exists when the scripting engine does not properly handle ob
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
In a web-based attack scenario, an attacker could host a website in an attempt to exploit the v
nvd
CVE-2019-1051MEDIUMCVSS 4.2fixed in 1.11.10fixed in publication2019-06-12
CVE-2019-1051 [MEDIUM] CWE-787 CVE-2019-1051: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd