VendorsMicrosoftedgeall versions
Vulnerabilities

Microsoft Edge

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

764CVEs
CVE-2015-6154
Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6150.
Published 2015-12-09 · Modified
9.3EPSS 0.165
CVE-2015-6155
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
Published 2015-12-09 · Modified
9.3EPSS 0.165
CVE-2015-6158
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140, CVE-2015-6142, CVE-2015-6143, CVE-2015-6153, CVE-2015-6159, and CVE-2015-6160.
Published 2015-12-09 · Modified
9.3EPSS 0.165
CVE-2015-2485
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2491 and CVE-2015-2541.
Published 2015-09-09 · Modified
9.3EPSS 0.165
CVE-2015-6073
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6068, CVE-2015-6072, CVE-2015-6075, CVE-2015-6077, CVE-2015-6079, CVE-2015-6080, and CVE-2015-6082.
Published 2015-11-11 · Modified
9.3EPSS 0.165
CVE-2015-6078
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6065.
Published 2015-11-11 · Modified
9.3EPSS 0.165
CVE-2016-3214
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3199.
Published 2016-06-16 · Modified
9.3EPSS 0.163
CVE-2015-2442
Microsoft Internet Explorer 8 through 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2444.
Published 2015-08-14 · Modified
9.3EPSS 0.156
CVE-2015-2446
Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2447.
Published 2015-08-14 · Modified
9.3EPSS 0.156
CVE-2015-6139
Microsoft Internet Explorer 11 and Microsoft Edge mishandle content types, which allows remote attackers to execute arbitrary web script in a privileged context via a crafted web site, aka "Microsoft Browser Elevation of Privilege Vulnerability."
Published 2015-12-09 · Modified
9.3EPSS 0.154
CVE-2018-0861
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0834, CVE-2018-0835, CVE-2018-0836, CVE-2018-0837, CVE-2018-0838, CVE-2018-0840, CVE-2018-0856, CVE-2018-0857, CVE-2018-0858, CVE-2018-0859, CVE-2018-0860, and CVE-2018-0866.
Published 2018-02-15 · Modified
9.3EPSS 0.148
CVE-2016-3331
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
Published 2016-10-14 · Modified
9.3EPSS 0.144
CVE-2017-0152
A remote code execution vulnerability exists in the way affected Microsoft scripting engine render when handling objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user, aka "Scripting Engine Memory Corruption Vulnerability."
Published 2017-07-14 · Modified
9.3EPSS 0.108
CVE-2020-0816
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'.
Published 2020-03-12 · Modified
9.3EPSS 0.107
CVE-2017-8660
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.
Published 2017-09-13 · Modified
9.3EPSS 0.101
CVE-2020-1073
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.
Published 2020-06-09 · Modified
9.3EPSS 0.086
CVE-2017-11827
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Microsoft browsers handle objects in memory, aka "Microsoft Browser Memory Corruption Vulnerability".
Published 2017-11-15 · Modified
9.3EPSS 0.076
CVE-2020-1555
Scripting Engine Memory Corruption Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.045
CVE-2020-1057
Scripting Engine Memory Corruption Vulnerability
Published 2020-09-11 · Modified
9.3EPSS 0.022
CVE-2019-0938
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.
Published 2019-05-16 · Modified
9.0EPSS 0.034
CVE-2016-7200
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Published 2016-11-10 · Analyzed
8.8KEV2 PoCEPSS 0.829
CVE-2021-26411
Internet Explorer Memory Corruption Vulnerability
Published 2021-03-11 · Analyzed
8.8KEVEPSS 0.808
CVE-2016-7201
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.
Published 2016-11-10 · Analyzed
8.8KEV2 PoCEPSS 0.801
CVE-2023-5217
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-09-28 · Analyzed
8.8KEVEPSS 0.490
CVE-2020-16009
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-11-03 · Analyzed
8.8KEVEPSS 0.483
CVE-2016-3297
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
Published 2016-09-14 · Modified
8.8EPSS 0.226
CVE-2019-0566
An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.
Published 2019-01-08 · Modified
8.81 PoCEPSS 0.186
CVE-2017-0002
Microsoft Edge allows remote attackers to bypass the Same Origin Policy via vectors involving the about:blank URL and data: URLs, aka "Microsoft Edge Elevation of Privilege Vulnerability."
Published 2017-01-10 · Modified
8.8EPSS 0.149
CVE-2021-21157
Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2021-02-22 · Modified
8.8EPSS 0.095
CVE-2021-30614
Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
Published 2021-09-03 · Modified
8.8EPSS 0.045
CVE-2021-30609
Chromium: CVE-2021-30609 Use after free in Sign-In
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30616
Chromium: CVE-2021-30616 Use after free in Media
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30610
Chromium: CVE-2021-30610 Use after free in Extensions API
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30613
Chromium: CVE-2021-30613 Use after free in Base internals
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30607
Chromium: CVE-2021-30607 Use after free in Permissions
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30624
Chromium: CVE-2021-30624 Use after free in Autofill
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30620
Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30618
Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30606
Chromium: CVE-2021-30606 Use after free in Blink
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30622
Chromium: CVE-2021-30622 Use after free in WebApp Installs
Published 2021-09-03 · Modified
8.8EPSS 0.041
← Prev2 / 20Next →