Skip to main content

Vendor/product archive

microsoft / edge CVEs

Beta · best-effort

761 CVEs tagged to microsoft / edge29 Critical, 499 High, 217 Medium, 16 Low, 0 Unrated.

CVE-2017-0069

Published Mar 17, 2017

Microsoft Edge allows remote attackers to spoof web content via a crafted web site, aka "Microsoft Edge Spoofing Vulnerability." This vulnerability is different from those describ…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-0068

Published Mar 17, 2017

Browsers in Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerabil…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0066

Published Mar 17, 2017

Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." Thi…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0065

Published Mar 17, 2017

Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." Th…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-0034

Published Mar 17, 2017

A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0033

Published Mar 17, 2017

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a crafted web site, aka "Microsoft Browser Spoofing Vulnerability." This vulnerab…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-0017

Published Mar 17, 2017

The RegEx class in the XSS filter in Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0015

Published Mar 17, 2017

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0012

Published Mar 17, 2017

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a crafted web site, aka "Microsoft Browser Spoofing Vulnerability." This vulnerab…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-0011

Published Mar 17, 2017

Microsoft Edge allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is dif…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0037

Published Feb 26, 2017

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in msh…

CVSS 8.1 · High
evidence mentions
10
Buzz score
58.5
KEV listed

CVE-2017-0002

Published Jan 10, 2017

Microsoft Edge allows remote attackers to bypass the Same Origin Policy via vectors involving the about:blank URL and data: URLs, aka "Microsoft Edge Elevation of Privilege Vulner…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-7297

Published Dec 20, 2016

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting En…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7296

Published Dec 20, 2016

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting En…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7288

Published Dec 20, 2016

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting En…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 576-600 of 761 CVEsPage 24 of 31