Microsoft
Microsoft Chakracore: vulnerabilidades y CVE
Microsoft Chakracore tiene 255 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE255
Últimos 12 meses0
Críticas3
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-8298 | Alta (7.5) | 75% | ⚠ Explotación activa | 11 jul 2018 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is… |
| CVE-2020-0878 | Alta (7.5) | 2.7% | ⚠ Explotación activa | 11 sept 2020 | <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-37143 | Media (5.5) | 0.84% | — | 18 jul 2023 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp(). |
| CVE-2023-37142 | Media (5.5) | 0.83% | — | 18 jul 2023 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees(). |
| CVE-2023-37141 | Media (5.5) | 0.83% | — | 18 jul 2023 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray(). |
| CVE-2023-37140 | Media (5.5) | 0.83% | — | 18 jul 2023 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount(). |
| CVE-2023-37139 | Media (5.5) | 0.86% | — | 18 jul 2023 | ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray(). |
| CVE-2020-23315 | Alta (7.5) | 2.4% | — | 20 ene 2022 | There is an ASSERTION (pFuncBody->GetYieldRegister() == oldYieldRegister) failed in Js::DebugContext::RundownSourcesAndReparse in ChakraCore version 1.12.0.0-beta. |
| CVE-2020-17131 | Alta (7.5) | 1.9% | — | 10 dic 2020 | Chakra Scripting Engine Memory Corruption Vulnerability |
| CVE-2020-17054 | Alta (7.5) | 2.1% | — | 11 nov 2020 | Chakra Scripting Engine Memory Corruption Vulnerability |
| CVE-2020-17048 | Alta (8.1) | 1.6% | — | 11 nov 2020 | Chakra Scripting Engine Memory Corruption Vulnerability |
| CVE-2020-1180 | Alta (7.5) | 2.1% | — | 11 sept 2020 | <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary… |
| CVE-2020-1172 | Alta (7.5) | 2.2% | — | 11 sept 2020 | <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary… |
| CVE-2020-1057 | Alta (8.1) | 2.2% | — | 11 sept 2020 | <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary… |
| CVE-2020-0878 | Alta (7.5) | 2.7% | ⚠ Explotación activa | 11 sept 2020 | <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the… |
| CVE-2020-1555 | Alta (8.8) | 4.5% | — | 17 ago 2020 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could… |
| CVE-2020-1219 | Alta (7.5) | 19% | — | 9 jun 2020 | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'. |
| CVE-2020-1073 | Alta (8.1) | 8.6% | — | 9 jun 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. |
| CVE-2020-1065 | Alta (7.5) | 2.2% | — | 21 may 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code… |
| CVE-2020-1037 | Alta (7.5) | 2.2% | — | 21 may 2020 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker… |
| CVE-2020-0970 | Alta (7.5) | 13% | — | 15 abr 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0968. |
| CVE-2020-0969 | Alta (7.5) | 13% | — | 15 abr 2020 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. |
| CVE-2020-0848 | Alta (7.5) | 9.6% | — | 12 mar 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,… |
| CVE-2020-0831 | Alta (7.5) | 8.9% | — | 12 mar 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,… |
| CVE-2020-0830 | Alta (7.5) | 8.7% | — | 12 mar 2020 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from… |
| CVE-2020-0829 | Alta (7.5) | 8.9% | — | 12 mar 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,… |
| CVE-2020-0828 | Alta (7.5) | 8.9% | — | 12 mar 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,… |
| CVE-2020-0827 | Alta (7.5) | 13% | — | 12 mar 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,… |
| CVE-2020-0826 | Alta (7.5) | 8.9% | — | 12 mar 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,… |
| CVE-2020-0825 | Alta (7.5) | 13% | — | 12 mar 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,… |
| CVE-2020-0823 | Alta (7.5) | 8.9% | — | 12 mar 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768,… |
| CVE-2020-0813 | Alta (7.5) | 5.5% | — | 12 mar 2020 | An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user’s computer or data.To exploit… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.