Vulnerabilities > Microsoft > Edge > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-12-20 CVE-2016-7282 Cross-site Scripting vulnerability in Microsoft Edge and Internet Explorer
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
network
low complexity
microsoft CWE-79
6.1
2016-12-20 CVE-2016-7281 7PK - Security Features vulnerability in Microsoft Edge and Internet Explorer
The Web Workers implementation in Microsoft Internet Explorer 10 and 11 and Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Browser Security Feature Bypass Vulnerability."
network
high complexity
microsoft CWE-254
5.3
2016-12-20 CVE-2016-7280 Cross-site Scripting vulnerability in Microsoft Edge
Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7206.
network
low complexity
microsoft CWE-79
6.1
2016-12-20 CVE-2016-7206 Cross-site Scripting vulnerability in Microsoft Edge
Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7280.
network
low complexity
microsoft CWE-79
6.1
2016-11-10 CVE-2016-7209 Improper Input Validation vulnerability in Microsoft Edge
Microsoft Edge allows remote attackers to spoof web content via a crafted web site, aka "Microsoft Edge Spoofing Vulnerability."
network
high complexity
microsoft CWE-20
5.3
2016-10-14 CVE-2016-3392 Improper Access Control vulnerability in Microsoft Edge
The Edge Content Security Policy feature in Microsoft Edge does not properly validate documents, which allows remote attackers to bypass intended access restrictions via a crafted web site, aka "Microsoft Browser Security Feature Bypass Vulnerability."
network
high complexity
microsoft CWE-284
5.3
2016-10-14 CVE-2016-3391 Information Exposure vulnerability in Microsoft Edge and Internet Explorer
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by leveraging access to a memory dump, aka "Microsoft Browser Information Disclosure Vulnerability."
network
high complexity
microsoft CWE-200
5.3
2016-10-14 CVE-2016-3388 Permissions, Privileges, and Access Controls vulnerability in Microsoft Edge and Internet Explorer
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3387.
network
high complexity
microsoft CWE-264
5.3
2016-10-14 CVE-2016-3267 Information Exposure vulnerability in Microsoft Edge and Internet Explorer
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of unspecified files via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
network
high complexity
microsoft CWE-200
5.3
2016-09-14 CVE-2016-3374 Information Exposure vulnerability in Microsoft products
The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3370.
network
low complexity
microsoft CWE-200
6.5