9.3
CVSSv2

CVE-2016-3386

Published: 14/10/2016 Updated: 12/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Chakra JavaScript engine in Microsoft Edge allows remote malicious users to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3389, CVE-2016-7190, and CVE-2016-7194.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft edge -

Exploits

<!-- Source: bugschromiumorg/p/project-zero/issues/detail?id=910 The spread operator in JavaScript allows an array to be treated as function parameters using the following syntax: var a = [1,2]; f(a); This is implemented in the JavascriptFunction::SpreadArgs function in Chakra (githubcom/Microsoft/ChakraCore/blob/master ...