Msrc Microsoft Edge Extended Stable vulnerabilities

54 known vulnerabilities affecting msrc/microsoft_edge_extended_stable.

Total CVEs
54
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH38MEDIUM13

Vulnerabilities

Page 3 of 3
CVE-2023-1216HIGHCVSS 8.82023-03-14
CVE-2023-1216 [HIGH] Chromium: CVE-2023-1216 Use after free in DevTools Chromium: CVE-2023-1216 Use after free in DevTools Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Ch
msrc
CVE-2023-1220HIGHCVSS 8.82023-03-14
CVE-2023-1220 [HIGH] Chromium: CVE-2023-1220 Heap buffer overflow in UMA Chromium: CVE-2023-1220 Heap buffer overflow in UMA Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (
msrc
CVE-2023-1532HIGHCVSS 8.82023-03-14
CVE-2023-1532 [HIGH] Chromium: CVE-2023-1532 Out of bounds read in GPU Video Chromium: CVE-2023-1532 Out of bounds read in GPU Video Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsof
msrc
CVE-2023-1217MEDIUMCVSS 6.52023-03-14
CVE-2023-1217 [MEDIUM] Chromium: CVE-2023-1217 Stack buffer overflow in Crash reporting Chromium: CVE-2023-1217 Stack buffer overflow in Crash reporting Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is
msrc
CVE-2023-28286MEDIUMCVSS 6.12023-03-14
CVE-2023-28286 [MEDIUM] Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability? The attacker is only able to modify the content of the vulnerable link to redirect the victim to a malicious site. FAQ: According to the CVSS metric, user interactio
msrc
CVE-2023-28261MEDIUMCVSS 5.72023-03-14
CVE-2023-28261 [MEDIUM] Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition and also to take additional actions prior to exploitation to prepare the target environment. FAQ: What privileges could be gaine
msrc
CVE-2023-1232MEDIUMCVSS 4.32023-03-14
CVE-2023-1232 [MEDIUM] Chromium: CVE-2023-1232 Insufficient policy enforcement in Resource Timing Chromium: CVE-2023-1232 Insufficient policy enforcement in Resource Timing Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Soft
msrc
CVE-2023-1228MEDIUMCVSS 4.32023-03-14
CVE-2023-1228 [MEDIUM] Chromium: CVE-2023-1228 Insufficient policy enforcement in Intents Chromium: CVE-2023-1228 Insufficient policy enforcement in Intents Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which
msrc
CVE-2023-0473HIGHCVSS 8.82023-01-10
CVE-2023-0473 [HIGH] Chromium: CVE-2023-0473: Type Confusion in ServiceWorker Chromium: CVE-2023-0473: Type Confusion in ServiceWorker Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Micros
msrc
CVE-2023-0474HIGHCVSS 8.82023-01-10
CVE-2023-0474 [HIGH] Chromium: CVE-2023-0474 Use after free in GuestView Chromium: CVE-2023-0474 Use after free in GuestView Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (
msrc
CVE-2023-0472HIGHCVSS 8.82023-01-10
CVE-2023-0472 [HIGH] Chromium: CVE-2023-0472 Use after free in WebRTC Chromium: CVE-2023-0472 Use after free in WebRTC Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: Why is this Chrome CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromi
msrc
CVE-2023-0471HIGHCVSS 8.82023-01-10
CVE-2023-0471 [HIGH] Chromium: CVE-2023-0471 Use after free in WebTransport Chromium: CVE-2023-0471 Use after free in WebTransport Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. FAQ: What is the version information for this release? Microsoft Edge Channel Microsoft Edge Version Based on Chromium Version Date Released Stable 109.0.1343.27 109.0.5414.11
msrc
CVE-2023-21796HIGHCVSS 8.32023-01-10
CVE-2023-21796 [HIGH] Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment. FAQ: According to the CVSS metric, a successful exploitation could lea
msrc
CVE-2023-21775HIGHCVSS 8.32023-01-10
CVE-2023-21775 [HIGH] Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment. FAQ: According to the CVSS metric, a successful exploitation could lead
msrc