This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Microsoft First view 2015-08-14
Product Edge Last view 2021-03-11
Version - Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:microsoft:edge

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
7.5 2021-03-11 CVE-2021-26411

Internet Explorer Memory Corruption Vulnerability

8.8 2021-02-22 CVE-2021-21157

Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

6.5 2021-02-09 CVE-2021-21141

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy via a crafted HTML page.

6.8 2021-02-09 CVE-2021-21140

Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device.

7.5 2021-01-12 CVE-2021-1705

Microsoft Edge (HTML-based) Memory Corruption Vulnerability

7.5 2020-12-10 CVE-2020-17131

Chakra Scripting Engine Memory Corruption Vulnerability

7.5 2020-11-11 CVE-2020-17058

Microsoft Browser Memory Corruption Vulnerability

7.5 2020-11-11 CVE-2020-17054

Chakra Scripting Engine Memory Corruption Vulnerability This CVE ID is unique from CVE-2020-17048.

8.1 2020-11-11 CVE-2020-17052

Scripting Engine Memory Corruption Vulnerability

8.1 2020-11-11 CVE-2020-17048

Chakra Scripting Engine Memory Corruption Vulnerability This CVE ID is unique from CVE-2020-17054.

8.8 2020-11-03 CVE-2020-16009

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

8.8 2020-09-11 CVE-2020-16884

A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory, aka 'Internet Explorer Browser Helper Object (BHO) Memory Corruption Vulnerability'.

8.1 2020-09-11 CVE-2020-1057

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1172, CVE-2020-1180.

7.5 2020-09-11 CVE-2020-0878

A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.

7.5 2020-08-17 CVE-2020-1569

A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'.

7.5 2020-08-17 CVE-2020-1568

A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF Remote Code Execution Vulnerability'.

8.8 2020-08-17 CVE-2020-1555

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1380, CVE-2020-1570.

4.3 2020-07-14 CVE-2020-1462

An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'.

6.5 2020-07-14 CVE-2020-1433

An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF Information Disclosure Vulnerability'.

5.3 2020-06-09 CVE-2020-1242

An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'.

6.1 2020-06-09 CVE-2020-1220

A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.

7.5 2020-06-09 CVE-2020-1219

A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.

8.1 2020-06-09 CVE-2020-1073

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.

5.9 2020-05-21 CVE-2020-1195

An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input, aka 'Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability'.

7.5 2020-05-21 CVE-2020-1096

A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF Remote Code Execution Vulnerability'.

CWE : Common Weakness Enumeration

%idName
43% (145) CWE-787 Out-of-bounds Write
33% (109) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
11% (38) CWE-200 Information Exposure
1% (6) CWE-290 Authentication Bypass by Spoofing
1% (4) CWE-346 Origin Validation Error
1% (4) CWE-254 Security Features
1% (4) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
0% (3) CWE-416 Use After Free
0% (3) CWE-264 Permissions, Privileges, and Access Controls
0% (3) CWE-125 Out-of-bounds Read
0% (3) CWE-20 Improper Input Validation
0% (2) CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
0% (1) CWE-665 Improper Initialization
0% (1) CWE-425 Direct Request ('Forced Browsing')
0% (1) CWE-287 Improper Authentication
0% (1) CWE-284 Access Control (Authorization) Issues
0% (1) CWE-88 Argument Injection or Modification
0% (1) CWE-19 Data Handling

Information Assurance Vulnerability Management (IAVM)

id Description
2015-A-0210 Cumulative Security Update for Microsoft Internet Explorer (MS15-094)
Severity: Category II - VMSKEY: V0061381
2015-A-0211 Cumulative Security Update for Microsoft Edge (MS15-095)
Severity: Category II - VMSKEY: V0061383
2015-A-0188 Cumulative Security Update for Microsoft Internet Explorer (MS15-079)
Severity: Category I - VMSKEY: V0061297
2015-A-0189 Cumulative Security Update for Microsoft Edge (MS15-091)
Severity: Category II - VMSKEY: V0061317

Snort® IPS/IDS

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
Date Description
2020-12-10 Microsoft Edge memory corruption attempt
RuleID : 56287 - Type : BROWSER-IE - Revision : 1
2020-12-10 Microsoft Edge memory corruption attempt
RuleID : 56286 - Type : BROWSER-IE - Revision : 1
2020-07-09 Microsoft Edge memory corruption attempt
RuleID : 54237 - Type : BROWSER-IE - Revision : 1
2020-07-09 Microsoft Edge memory corruption attempt
RuleID : 54236 - Type : BROWSER-IE - Revision : 1
2020-03-03 Microsoft Edge scripting engine memory corruption attempt
RuleID : 52989 - Type : BROWSER-IE - Revision : 1
2020-03-03 Microsoft Edge scripting engine memory corruption attempt
RuleID : 52988 - Type : BROWSER-IE - Revision : 1
2020-03-03 Microsoft Edge scripting engine memory corruption attempt
RuleID : 52987 - Type : BROWSER-IE - Revision : 1
2020-03-03 Microsoft Edge scripting engine memory corruption attempt
RuleID : 52986 - Type : BROWSER-IE - Revision : 1
2020-02-18 Microsoft Edge scripting engine memory corruption attempt
RuleID : 52611 - Type : BROWSER-IE - Revision : 1
2020-02-18 Microsoft Edge scripting engine memory corruption attempt
RuleID : 52610 - Type : BROWSER-IE - Revision : 1
2020-02-14 Microsoft Edge out of bounds write attempt
RuleID : 52607 - Type : BROWSER-IE - Revision : 1
2020-02-14 Microsoft Edge out of bounds write attempt
RuleID : 52606 - Type : BROWSER-IE - Revision : 1
2020-01-23 Microsoft Edge Chakra EmitCall memory corruption attempt
RuleID : 52511 - Type : BROWSER-IE - Revision : 1
2020-01-23 Microsoft Edge Chakra EmitCall memory corruption attempt
RuleID : 52510 - Type : BROWSER-IE - Revision : 1
2020-01-23 Microsoft Edge Chakra EmitCall memory corruption attempt
RuleID : 52509 - Type : BROWSER-IE - Revision : 1
2020-01-23 Microsoft Edge Chakra EmitCall memory corruption attempt
RuleID : 52508 - Type : BROWSER-IE - Revision : 1
2020-01-16 Microsoft Edge out of bounds write attempt
RuleID : 52475 - Type : BROWSER-IE - Revision : 1
2020-01-16 Microsoft Edge out of bounds write attempt
RuleID : 52474 - Type : BROWSER-IE - Revision : 1
2019-12-05 Microsoft Edge scripting engine Map prototype memory corruption attempt
RuleID : 52085 - Type : BROWSER-IE - Revision : 1
2019-12-05 Microsoft Edge scripting engine Map prototype memory corruption attempt
RuleID : 52084 - Type : BROWSER-IE - Revision : 1
2019-11-12 Microsoft Edge defineGetter type confusion attempt
RuleID : 51815 - Type : BROWSER-IE - Revision : 1
2019-11-12 Microsoft Edge defineGetter type confusion attempt
RuleID : 51814 - Type : BROWSER-IE - Revision : 1
2019-10-10 Microsoft Edge print function information disclosure attempt
RuleID : 51459 - Type : BROWSER-IE - Revision : 1
2019-10-10 Microsoft Edge print function information disclosure attempt
RuleID : 51458 - Type : BROWSER-IE - Revision : 1
2019-10-08 Microsoft Edge scripting engine memory corruption attempt
RuleID : 51426 - Type : BROWSER-IE - Revision : 1

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2018-08-28 Name: The version of Microsoft Edge web browser installed on the remote host is no ...
File: microsoft_edge_web_browser_win_unsupported.nasl - Type: ACT_GATHER_INFO
2017-12-12 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_dec_4053580.nasl - Type: ACT_GATHER_INFO
2017-12-12 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_dec_4053578.nasl - Type: ACT_GATHER_INFO
2017-12-12 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_dec_4053579.nasl - Type: ACT_GATHER_INFO
2017-12-12 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_dec_4053581.nasl - Type: ACT_GATHER_INFO
2017-12-12 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_dec_4054517.nasl - Type: ACT_GATHER_INFO
2017-12-12 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_dec_4054518.nasl - Type: ACT_GATHER_INFO
2017-12-12 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_dec_4054519.nasl - Type: ACT_GATHER_INFO
2017-12-12 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_dec_4054520.nasl - Type: ACT_GATHER_INFO
2017-12-12 Name: The Internet Explorer installation on the remote host is affected by multiple...
File: smb_nt_ms17_dec_internet_explorer.nasl - Type: ACT_GATHER_INFO
2017-11-30 Name: The Internet Explorer installation on the remote host is affected by multiple...
File: smb_nt_ms17_nov_internet_explorer.nasl - Type: ACT_GATHER_INFO
2017-11-30 Name: The Internet Explorer installation on the remote host is affected by multiple...
File: smb_nt_ms17_jun_internet_explorer.nasl - Type: ACT_GATHER_INFO
2017-11-30 Name: The Internet Explorer installation on the remote host is affected by multiple...
File: smb_nt_ms17_aug_internet_explorer.nasl - Type: ACT_GATHER_INFO
2017-11-14 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_nov_4048953.nasl - Type: ACT_GATHER_INFO
2017-11-14 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_nov_4048952.nasl - Type: ACT_GATHER_INFO
2017-11-14 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_nov_4048954.nasl - Type: ACT_GATHER_INFO
2017-11-14 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_nov_4048955.nasl - Type: ACT_GATHER_INFO
2017-11-14 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_nov_4048957.nasl - Type: ACT_GATHER_INFO
2017-11-14 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_nov_4048958.nasl - Type: ACT_GATHER_INFO
2017-11-14 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_nov_4048959.nasl - Type: ACT_GATHER_INFO
2017-11-14 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_nov_4048956.nasl - Type: ACT_GATHER_INFO
2017-11-03 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_jul_4025338.nasl - Type: ACT_GATHER_INFO
2017-11-03 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_aug_4034668.nasl - Type: ACT_GATHER_INFO
2017-08-08 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_aug_4034664.nasl - Type: ACT_GATHER_INFO
2017-08-08 Name: The remote Windows host is affected by multiple vulnerabilities.
File: smb_nt_ms17_aug_4034658.nasl - Type: ACT_GATHER_INFO