« Volver al listado

Microsoft

Microsoft Chakracore: vulnerabilidades y CVE

Microsoft Chakracore tiene 255 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE255
Últimos 12 meses0
Críticas3
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2018-8298Alta (7.5)75%⚠ Explotación activa11 jul 2018
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is…
CVE-2020-0878Alta (7.5)2.7%⚠ Explotación activa11 sept 2020
<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-37143Media (5.5)0.84%—18 jul 2023
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp().
CVE-2023-37142Media (5.5)0.83%—18 jul 2023
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees().
CVE-2023-37141Media (5.5)0.83%—18 jul 2023
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray().
CVE-2023-37140Media (5.5)0.83%—18 jul 2023
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount().
CVE-2023-37139Media (5.5)0.86%—18 jul 2023
ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray().
CVE-2020-23315Alta (7.5)2.4%—20 ene 2022
There is an ASSERTION (pFuncBody->GetYieldRegister() == oldYieldRegister) failed in Js::DebugContext::RundownSourcesAndReparse in ChakraCore version 1.12.0.0-beta.
CVE-2020-17131Alta (7.5)1.9%—10 dic 2020
Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2020-17054Alta (7.5)2.1%—11 nov 2020
Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2020-17048Alta (8.1)1.6%—11 nov 2020
Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2020-1180Alta (7.5)2.1%—11 sept 2020
<p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary…
CVE-2020-1172Alta (7.5)2.2%—11 sept 2020
<p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary…
CVE-2020-1057Alta (8.1)2.2%—11 sept 2020
<p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary…
CVE-2020-0878Alta (7.5)2.7%⚠ Explotación activa11 sept 2020
<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the…
CVE-2020-1555Alta (8.8)4.5%—17 ago 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could…
CVE-2020-1219Alta (7.5)19%—9 jun 2020
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.
CVE-2020-1073Alta (8.1)8.6%—9 jun 2020
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.
CVE-2020-1065Alta (7.5)2.2%—21 may 2020
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code…
CVE-2020-1037Alta (7.5)2.2%—21 may 2020
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker…
CVE-2020-0970Alta (7.5)13%—15 abr 2020
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0968.
CVE-2020-0969Alta (7.5)13%—15 abr 2020
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'.
CVE-2020-0848Alta (7.5)9.6%—12 mar 2020
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,…
CVE-2020-0831Alta (7.5)8.9%—12 mar 2020
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,…
CVE-2020-0830Alta (7.5)8.7%—12 mar 2020
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from…
CVE-2020-0829Alta (7.5)8.9%—12 mar 2020
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,…
CVE-2020-0828Alta (7.5)8.9%—12 mar 2020
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,…
CVE-2020-0827Alta (7.5)13%—12 mar 2020
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,…
CVE-2020-0826Alta (7.5)8.9%—12 mar 2020
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,…
CVE-2020-0825Alta (7.5)13%—12 mar 2020
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,…
CVE-2020-0823Alta (7.5)8.9%—12 mar 2020
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,…
CVE-2020-0813Alta (7.5)5.5%—12 mar 2020
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user’s computer or data.To exploit…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1499.004 Application or System Exploitation5
  2. T1574 Hijack Execution Flow5
  3. T1189 Drive-by Compromise4
  4. T1203 Exploitation for Client Execution4
  5. T1204.002 Malicious File3
  6. T1059 Command and Scripting Interpreter2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft