Msrc Microsoft Edge vulnerabilities
1,721 known vulnerabilities affecting msrc/microsoft_edge.
Total CVEs
1,721
CISA KEV
58
actively exploited
Public exploits
16
Exploited in wild
48
Severity breakdown
CRITICAL66HIGH965MEDIUM659LOW24UNKNOWN7
Vulnerabilities
Page 19 of 87
CVE-2024-9602HIGHCVSS 8.82024-10-08
CVE-2024-9602 [HIGH] Chromium: CVE-2024-9602 Type Confusion in V8
Chromium: CVE-2024-9602 Type Confusion in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
129.0.2792.89
10/10/2024
129.0.6668.100/.101
FAQ: Why is this Chrome CVE in
msrc
CVE-2024-9965HIGHCVSS 8.82024-10-08
CVE-2024-9965 [HIGH] Chromium: CVE-2024-9965 Insufficient data validation in DevTools
Chromium: CVE-2024-9965 Insufficient data validation in DevTools
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17/2024
130.0.6723.5
msrc
CVE-2024-10231HIGHCVSS 8.82024-10-08
CVE-2024-10231 [HIGH] Chromium: CVE -2024-10231 Type Confusion in V8
Chromium: CVE -2024-10231 Type Confusion in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-
msrc
CVE-2024-43579HIGHCVSS 7.62024-10-08
CVE-2024-43579 [HIGH] CWE-122 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17/2024
130.0.6723.59
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to a high loss of confidentiality (C:H), and integrity (I:H) and some loss of
msrc
CVE-2024-10229HIGHCVSS 8.12024-10-08
CVE-2024-10229 [HIGH] Chromium: CVE -2024-10229 Inappropriate implementation in Extensions
Chromium: CVE -2024-10229 Inappropriate implementation in Extensions
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) wh
msrc
CVE-2024-10230HIGHCVSS 8.82024-10-08
CVE-2024-10230 [HIGH] Chromium: CVE -2024-10230 Type Confusion in V8
Chromium: CVE -2024-10230 Type Confusion in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-
msrc
CVE-2024-43566HIGHCVSS 7.52024-10-08
CVE-2024-43566 [HIGH] CWE-190 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17/2024
130.0.6723.59
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and user interaction is required (UI:R). What is the target context of the remote code execution?
S
msrc
CVE-2024-43580MEDIUMCVSS 5.42024-10-08
CVE-2024-43580 [MEDIUM] CWE-357 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to minor loss of confidentiality (C:L), integrity (I:L), and availability (A:N). What does that mean for this vulnerability?
Successful exploitation of this vulnerability has limited impacts to Confidentiality and Integrity and no impact on Availability. An attack
msrc
CVE-2024-43577MEDIUMCVSS 4.32024-10-08
CVE-2024-43577 [MEDIUM] CWE-449 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker would have to send the victim a malicious file that the victim would have to execute.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17/
msrc
CVE-2024-9963MEDIUMCVSS 4.32024-10-08
CVE-2024-9963 [MEDIUM] Chromium: CVE-2024-9963 Insufficient data validation in Downloads
Chromium: CVE-2024-9963 Insufficient data validation in Downloads
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17/2024
130.0.67
msrc
CVE-2024-9964MEDIUMCVSS 4.32024-10-08
CVE-2024-9964 [MEDIUM] Chromium: CVE-2024-9964 Inappropriate implementation in Payments
Chromium: CVE-2024-9964 Inappropriate implementation in Payments
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17/2024
130.0.6723
msrc
CVE-2024-9958MEDIUMCVSS 4.32024-10-08
CVE-2024-9958 [MEDIUM] Chromium: CVE-2024-9958 Inappropriate implementation in PictureInPicture
Chromium: CVE-2024-9958 Inappropriate implementation in PictureInPicture
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17
msrc
CVE-2024-43595MEDIUMCVSS 6.52024-10-08
CVE-2024-43595 [MEDIUM] CWE-126 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and user interaction is required (UI:R). What is the
msrc
CVE-2024-43587MEDIUMCVSS 5.92024-10-08
CVE-2024-43587 [MEDIUM] CWE-122 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17/2024
130.0.6723.59
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requi
msrc
CVE-2024-49023MEDIUMCVSS 5.92024-10-08
CVE-2024-49023 [MEDIUM] CWE-416 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17/2024
130.0.6723.59
FAQ: How could an attacker exploit this vulnerability via the Network?
An attacker could host a specially crafted website designed to exploit the vulnerability through
msrc
CVE-2024-9966MEDIUMCVSS 5.32024-10-08
CVE-2024-9966 [MEDIUM] Chromium: CVE-2024-9966 Inappropriate implementation in Navigations
Chromium: CVE-2024-9966 Inappropriate implementation in Navigations
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17/2024
130.
msrc
CVE-2024-43596MEDIUMCVSS 6.52024-10-08
CVE-2024-43596 [MEDIUM] CWE-843 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17/2024
130.0.6723.59
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and user interaction is required (UI:R). What is the target context of the remote code execution?
msrc
CVE-2024-9962MEDIUMCVSS 4.32024-10-08
CVE-2024-9962 [MEDIUM] Chromium: CVE-2024-9962 Inappropriate implementation in Permissions
Chromium: CVE-2024-9962 Inappropriate implementation in Permissions
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
130.0.2849.46
10/17/2024
130.
msrc
CVE-2024-9370UNKNOWN2024-10-08
CVE-2024-9370 Chromium: CVE-2024-9370 Inappropriate implementation in V8
Chromium: CVE-2024-9370 Inappropriate implementation in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft
msrc
CVE-2024-7970HIGHCVSS 8.82024-09-10
CVE-2024-7970 [HIGH] Chromium: CVE-2024-7970 Out of bounds write in V8
Chromium: CVE-2024-7970 Out of bounds write in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chro
msrc