cbcvebase.

Microsoft Edge vulnerabilities

43 known vulnerabilities affecting microsoft/edge.

Total CVEs
43
CISA KEV
4
actively exploited
Public exploits
2
Exploited in wild
4
Severity breakdown
CRITICAL2HIGH20MEDIUM19LOW2

Vulnerabilities

Page 1 of 3
CVE-2023-5217P1HIGHCVSS 8.8KEVPoCv116.0.1938.98v117.0.2045.472023-09-28
CVE-2023-5217 [HIGH] CWE-787 CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1 Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7971P1CRITICALCVSS 9.6KEVPoCfixed in 128.0.2739.422024-08-21
CVE-2024-7971 [CRITICAL] CWE-843 CVE-2024-7971: Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit he Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-16009P1HIGHCVSS 8.8KEVfixed in 86.0.622.632020-11-03
CVE-2020-16009 [HIGH] CWE-787 CVE-2020-16009: Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-4135P1CRITICALCVSS 9.6KEVfixed in 107.0.1418.622022-11-25
CVE-2022-4135 [CRITICAL] CWE-787 CVE-2022-4135: Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who h Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-21157P3HIGHCVSS 8.8fixed in 88.0.705.742021-02-22
CVE-2021-21157 [HIGH] CWE-416 CVE-2021-21157: Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote atta Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-38669P3HIGHCVSS 8.8fixed in 93.0.961.442021-09-15
CVE-2021-38669 [HIGH] CVE-2021-38669: Microsoft Edge (Chromium-based) Tampering Vulnerability Microsoft Edge (Chromium-based) Tampering Vulnerability
nvd
CVE-2021-30614P3HIGHCVSS 8.8≤ 93.0.961.382021-09-03
CVE-2021-30614 [HIGH] CWE-787 CVE-2021-30614: Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
nvd
CVE-2021-30610P3HIGHCVSS 8.8≤ 93.0.961.382021-09-03
CVE-2021-30610 [HIGH] CWE-416 CVE-2021-30610: Chromium: CVE-2021-30610 Use after free in Extensions API Chromium: CVE-2021-30610 Use after free in Extensions API
nvd
CVE-2021-30620P3HIGHCVSS 8.8≤ 93.0.961.382021-09-03
CVE-2021-30620 [HIGH] CVE-2021-30620: Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
nvd
CVE-2021-26436P3HIGHCVSS 8.1fixed in 93.0.961.382021-09-02
CVE-2021-26436 [HIGH] CVE-2021-26436: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2021-30618P3HIGHCVSS 8.8≤ 93.0.961.382021-09-03
CVE-2021-30618 [HIGH] CVE-2021-30618: Chromium: CVE-2021-30618 Inappropriate implementation in DevTools Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
nvd
CVE-2021-30608P3HIGHCVSS 8.8≤ 93.0.961.382021-09-03
CVE-2021-30608 [HIGH] CWE-416 CVE-2021-30608: Chromium: CVE-2021-30608 Use after free in Web Share Chromium: CVE-2021-30608 Use after free in Web Share
nvd
CVE-2022-44708P3HIGHCVSS 8.3fixed in 108.0.1462.422022-12-13
CVE-2022-44708 [HIGH] CVE-2022-44708: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2021-30609P3HIGHCVSS 8.8≤ 93.0.961.382021-09-03
CVE-2021-30609 [HIGH] CWE-416 CVE-2021-30609: Chromium: CVE-2021-30609 Use after free in Sign-In Chromium: CVE-2021-30609 Use after free in Sign-In
nvd
CVE-2021-30613P3HIGHCVSS 8.8≤ 93.0.961.382021-09-03
CVE-2021-30613 [HIGH] CWE-416 CVE-2021-30613: Chromium: CVE-2021-30613 Use after free in Base internals Chromium: CVE-2021-30613 Use after free in Base internals
nvd
CVE-2021-30624P3HIGHCVSS 8.8≤ 93.0.961.382021-09-03
CVE-2021-30624 [HIGH] CWE-416 CVE-2021-30624: Chromium: CVE-2021-30624 Use after free in Autofill Chromium: CVE-2021-30624 Use after free in Autofill
nvd
CVE-2021-30622P3HIGHCVSS 8.8≤ 93.0.961.382021-09-03
CVE-2021-30622 [HIGH] CWE-416 CVE-2021-30622: Chromium: CVE-2021-30622 Use after free in WebApp Installs Chromium: CVE-2021-30622 Use after free in WebApp Installs
nvd
CVE-2021-30623P3HIGHCVSS 8.8≤ 93.0.961.382021-09-03
CVE-2021-30623 [HIGH] CWE-416 CVE-2021-30623: Chromium: CVE-2021-30623 Use after free in Bookmarks Chromium: CVE-2021-30623 Use after free in Bookmarks
nvd
CVE-2021-30607P3HIGHCVSS 8.8≤ 93.0.961.382021-09-03
CVE-2021-30607 [HIGH] CWE-416 CVE-2021-30607: Chromium: CVE-2021-30607 Use after free in Permissions Chromium: CVE-2021-30607 Use after free in Permissions
nvd
CVE-2024-41879P3HIGHCVSS 7.8fixed in 128.0.2739.422024-08-26
CVE-2024-41879 [HIGH] CWE-787 CVE-2024-41879: Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerabil Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
Microsoft Edge vulnerabilities | cvebase