935
VMScore

CVE-2016-7189

Published: 14/10/2016 Updated: 12/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Chakra JavaScript engine in Microsoft Edge allows remote malicious users to execute arbitrary code via a crafted web site, aka "Scripting Engine Remote Code Execution Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft edge -

Exploits

<!-- Source: bugschromiumorg/p/project-zero/issues/detail?id=919 When an array is joined in Chakra, it calls JavascriptArray::JoinArrayHelper, a function that is templated based on the type of the array This function then calls JavascriptArray::TemplatedGetItem to get each item in the array If an element is missing from the array, t ...