Vulnerabilities > Microsoft > Chakracore > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-06-09 CVE-2020-1073 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Chakracore and Edge
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.
network
microsoft CWE-119
critical
9.3
2018-10-10 CVE-2018-8500 Out-of-bounds Write vulnerability in Microsoft Chakracore
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore.
network
low complexity
microsoft CWE-787
critical
10.0
2018-02-15 CVE-2018-0834 Out-of-bounds Write vulnerability in Microsoft Chakracore and Edge
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".
network
microsoft CWE-787
critical
9.3
2018-02-15 CVE-2018-0858 Out-of-bounds Write vulnerability in Microsoft Chakracore
ChakraCore allows remote code execution, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".
network
microsoft CWE-787
critical
9.3
2017-11-02 CVE-2017-11767 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Chakracore
ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".
network
low complexity
microsoft CWE-119
critical
10.0
2017-10-13 CVE-2017-11812 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Chakracore and Edge
ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".
network
microsoft CWE-119
critical
9.3
2017-08-11 CVE-2017-8658 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Chakracore
A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".
network
low complexity
microsoft CWE-119
critical
10.0