Msrc Microsoft Edge vulnerabilities

1,721 known vulnerabilities affecting msrc/microsoft_edge.

Total CVEs
1,721
CISA KEV
58
actively exploited
Public exploits
16
Exploited in wild
48
Severity breakdown
CRITICAL66HIGH965MEDIUM659LOW24UNKNOWN7

Vulnerabilities

Page 22 of 87
CVE-2024-7532HIGHCVSS 8.82024-08-13
CVE-2024-7532 [HIGH] Chromium: CVE-2024-7533 Use after free in Sharing Chromium: CVE-2024-7533 Use after free in Sharing Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: What is the version information for this release? Microsoft Edge Channel Microsoft Edge Version Based on Chromium Version Date Released Stable 127.0.2651.98 127.0.6533.99/.100 8/8/
msrc
CVE-2024-7964HIGHCVSS 8.82024-08-13
CVE-2024-7964 [HIGH] Chromium: CVE-2024-7964 Use after free in Passwords Chromium: CVE-2024-7964 Use after free in Passwords Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (
msrc
CVE-2024-7965HIGHCVSS 8.8KEV2024-08-13
CVE-2024-7965 [HIGH] Chromium: CVE-2024-7965 Inappropriate implementation in V8 Chromium: CVE-2024-7965 Inappropriate implementation in V8 Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Mi
msrc
CVE-2024-38218HIGHCVSS 8.42024-08-13
CVE-2024-38218 [HIGH] CWE-843 Microsoft Edge (HTML-based) Memory Corruption Vulnerability Microsoft Edge (HTML-based) Memory Corruption Vulnerability FAQ: What is the version information for this release? Microsoft Edge Channel Microsoft Edge Version Based on Chromium Version Date Released Stable 127.0.2651.98 127.0.6533.99/.100 8/8/2024 FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remo
msrc
CVE-2024-7967HIGHCVSS 8.82024-08-13
CVE-2024-7967 [HIGH] Chromium: CVE-2024-7967 Heap buffer overflow in Fonts Chromium: CVE-2024-7967 Heap buffer overflow in Fonts Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Ed
msrc
CVE-2024-7973HIGHCVSS 8.82024-08-13
CVE-2024-7973 [HIGH] Chromium: CVE-2024-7973 Heap buffer overflow in PDFium Chromium: CVE-2024-7973 Heap buffer overflow in PDFium Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft
msrc
CVE-2024-38219MEDIUMCVSS 6.52024-08-13
CVE-2024-38219 [MEDIUM] CWE-843 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to minor loss of confidentiality (C:L), integrity (I:L) and availability (A:L). What does that mean for this vulnerability? While we cannot rule out the impact to Confidentiality, Integrity, and Availability, the ability to exploit this v
msrc
CVE-2024-41879MEDIUMCVSS 7.82024-08-13
CVE-2024-41879 [HIGH] CWE-125 Adobe Systems Incorporated: CVE-2024-41879 Adobe PDF Viewer Remote Code Execution Vulnerability Adobe Systems Incorporated: CVE-2024-41879 Adobe PDF Viewer Remote Code Execution Vulnerability FAQ: What is the version information for this release? Microsoft Edge Channel Microsoft Edge Version Based on Chromium Version Date Released Stable 128.0.2739.42 128.0.6613.84/.85 8/22/2024 FAQ: Why is this Adobe CVE included in the Security Update Guide? The vulnerabili
msrc
CVE-2024-7976MEDIUMCVSS 4.32024-08-13
CVE-2024-7976 [MEDIUM] Chromium: CVE-2024-7976 Inappropriate implementation in FedCM Chromium: CVE-2024-7976 Inappropriate implementation in FedCM Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consum
msrc
CVE-2024-43472MEDIUMCVSS 5.82024-08-13
CVE-2024-43472 [MEDIUM] CWE-416 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability. FAQ: What privileges could be gained by an attacker who successfully exploited
msrc
CVE-2024-7981MEDIUMCVSS 4.32024-08-13
CVE-2024-7981 [MEDIUM] Chromium: CVE-2024-7981 Inappropriate implementation in Views Chromium: CVE-2024-7981 Inappropriate implementation in Views Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consum
msrc
CVE-2024-7978MEDIUMCVSS 4.32024-08-13
CVE-2024-7978 [MEDIUM] Chromium: CVE-2024-7978 Insufficient policy enforcement in Data Transfer Chromium: CVE-2024-7978 Insufficient policy enforcement in Data Transfer Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software
msrc
CVE-2024-8035MEDIUMCVSS 4.32024-08-13
CVE-2024-8035 [MEDIUM] Chromium: CVE-2024-8035 Inappropriate implementation in Extensions Chromium: CVE-2024-8035 Inappropriate implementation in Extensions Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which
msrc
CVE-2024-8034MEDIUMCVSS 4.32024-08-13
CVE-2024-8034 [MEDIUM] Chromium: CVE-2024-8034 Inappropriate implementation in Custom Tabs Chromium: CVE-2024-8034 Inappropriate implementation in Custom Tabs Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) whi
msrc
CVE-2024-7975MEDIUMCVSS 4.32024-08-13
CVE-2024-7975 [MEDIUM] Chromium: CVE-2024-7975 Inappropriate implementation in Permissions Chromium: CVE-2024-7975 Inappropriate implementation in Permissions Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) whi
msrc
CVE-2024-8033MEDIUMCVSS 4.32024-08-13
CVE-2024-8033 [MEDIUM] Chromium: CVE-2024-8033 Inappropriate implementation in WebApp Installs Chromium: CVE-2024-8033 Inappropriate implementation in WebApp Installs Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (
msrc
CVE-2024-38207MEDIUMCVSS 6.32024-08-13
CVE-2024-38207 [MEDIUM] CWE-843 Microsoft Edge (HTML-based) Memory Corruption Vulnerability Microsoft Edge (HTML-based) Memory Corruption Vulnerability FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to minor loss of confidentiality (C:L), integrity (I:L) and availability (A:L). What does that mean for this vulnerability? While we cannot rule out the impact to Confidentiality, Integrity, and Availability, the ability to exploit this vulnerability by
msrc
CVE-2024-6779CRITICALCVSS 9.62024-07-09
CVE-2024-6779 [CRITICAL] Chromium: CVE-2024-6779 Out of bounds memory access in V8 Chromium: CVE-2024-6779 Out of bounds memory access in V8 Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by
msrc
CVE-2024-6778HIGHCVSS 7.52024-07-09
CVE-2024-6778 [HIGH] Chromium: CVE-2024-6778 Race in DevTools Chromium: CVE-2024-6778 Race in DevTools Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is
msrc
CVE-2024-6988HIGHCVSS 8.82024-07-09
CVE-2024-6988 [HIGH] Chromium: CVE-2024-6988 Use after free in Downloads Chromium: CVE-2024-6988 Use after free in Downloads Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (
msrc