Microsoft.ChakraCore
NuGet247 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting Microsoft.ChakraCorepage 5 of 5
- CVE-2019-1138HIGHCVSS 7.5EG 7.5fixed in 1.11.132019-09-11
vulnerable: 1.10.0 ... 1.8.5 (49 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1217, …
- CVE-2019-1139MEDIUMCVSS 4.2EG 4.2fixed in 1.11.122019-08-14
vulnerable: 1.10.0 ... 1.8.5 (48 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrar…
- CVE-2019-1140HIGHCVSS 8.8EG 8.8fixed in 1.11.122019-08-14
vulnerable: 1.10.0 ... 1.8.5 (48 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrar…
- CVE-2019-1141MEDIUMCVSS 4.2EG 4.2fixed in 1.11.122019-08-14
vulnerable: 1.10.0 ... 1.8.5 (48 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrar…
- CVE-2019-1195MEDIUMCVSS 4.2EG 4.2fixed in 1.11.122019-08-14
vulnerable: 1.10.0 ... 1.8.5 (48 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrar…
- CVE-2019-1196MEDIUMCVSS 4.2EG 4.2fixed in 1.11.122019-08-14
vulnerable: 1.10.0 ... 1.8.5 (48 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrar…
- CVE-2019-1197MEDIUMCVSS 4.2EG 4.2fixed in 1.11.122019-08-14
vulnerable: 1.10.0 ... 1.8.5 (48 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrar…
- CVE-2019-1217HIGHCVSS 7.5EG 7.5fixed in 1.11.132019-09-11
vulnerable: 1.10.0 ... 1.8.5 (49 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, …
- CVE-2019-1237HIGHCVSS 7.5EG 7.5fixed in 1.11.132019-09-11
vulnerable: 1.10.0 ... 1.8.5 (49 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, …
- CVE-2019-1298HIGHCVSS 7.5EG 7.5fixed in 1.11.132019-09-11
vulnerable: 1.10.0 ... 1.8.5 (49 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, …
- CVE-2019-1300HIGHCVSS 7.5EG 7.5fixed in 1.11.132019-09-11
vulnerable: 1.10.0 ... 1.8.5 (49 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, …
- CVE-2019-1307HIGHCVSS 7.5EG 7.5fixed in 1.11.142019-10-10
vulnerable: 1.10.0 ... 1.8.5 (50 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1308, …
- CVE-2019-1308HIGHCVSS 7.5EG 7.5fixed in 1.11.142019-10-10
vulnerable: 1.10.0 ... 1.8.5 (50 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1307, …
- CVE-2019-1335HIGHCVSS 7.5EG 7.5fixed in 1.11.142019-10-10
vulnerable: 1.10.0 ... 1.8.5 (50 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1307, …
- CVE-2019-1366HIGHCVSS 7.5EG 7.5fixed in 1.11.142019-10-10
vulnerable: 1.10.0 ... 1.8.5 (50 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1307, …
- CVE-2020-0710HIGHCVSS 7.5EG 7.5fixed in 1.11.162020-02-11
vulnerable: 1.10.0 ... 1.8.5 (52 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-20…
- CVE-2020-0711HIGHCVSS 7.5EG 7.5fixed in 1.11.162020-02-11
vulnerable: 1.10.0 ... 1.8.5 (52 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-20…
- CVE-2020-0712HIGHCVSS 7.5EG 7.5fixed in 1.11.162020-02-11
vulnerable: 1.10.0 ... 1.8.5 (52 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-20…
- CVE-2020-0713HIGHCVSS 7.5EG 7.5fixed in 1.11.162020-02-11
vulnerable: 1.10.0 ... 1.8.5 (52 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-20…
- CVE-2020-0767HIGHCVSS 7.5EG 7.5fixed in 1.11.162020-02-11
vulnerable: 1.10.0 ... 1.8.5 (52 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-20…
- CVE-2020-0768HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0823, CVE-2020-0825, …
- CVE-2020-0811HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from C…
- CVE-2020-0812HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from C…
- CVE-2020-0813HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user’s computer or data.To exploit the vulnerabil…
- CVE-2020-0823HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0825, CVE-20…
- CVE-2020-0825HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-20…
- CVE-2020-0826HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-20…
- CVE-2020-0827HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-20…
- CVE-2020-0828HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-20…
- CVE-2020-0829HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-20…
- CVE-2020-0830HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, …
- CVE-2020-0831HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-20…
- CVE-2020-0832HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-08…
- CVE-2020-0833HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-08…
- CVE-2020-0848HIGHCVSS 7.5EG 7.5fixed in 1.11.172020-03-12
vulnerable: 1.10.0 ... 1.8.5 (53 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-20…
- CVE-2020-0969HIGHCVSS 7.5EG 7.5fixed in 1.11.182020-04-15
vulnerable: 1.10.0 ... 1.8.5 (54 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'.
- CVE-2020-0970HIGHCVSS 7.5EG 7.5fixed in 1.11.182020-04-15
vulnerable: 1.10.0 ... 1.8.5 (54 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0968.
- CVE-2020-1037HIGHCVSS 7.5EG 7.5fixed in 1.11.192020-05-21
vulnerable: 1.10.0 ... 1.8.5 (55 versions)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrar…
- CVE-2020-1057MEDIUMCVSS 4.2EG 4.2fixed in 1.11.222020-09-11
vulnerable: 1.10.0 ... 1.8.5 (58 versions)
<p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of…
- CVE-2020-1065HIGHCVSS 7.5EG 7.5fixed in 1.11.192020-05-21
vulnerable: 1.10.0 ... 1.8.5 (55 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of th…
- CVE-2020-1073HIGHCVSS 8.1EG 8.1fixed in 1.11.202020-06-09
vulnerable: 1.10.0 ... 1.8.5 (56 versions)
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.
- CVE-2020-1172MEDIUMCVSS 4.2EG 4.2fixed in 1.11.222020-09-11
vulnerable: 1.10.0 ... 1.8.5 (58 versions)
<p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of…
- CVE-2020-1180MEDIUMCVSS 4.2EG 4.2fixed in 1.11.222020-09-11
vulnerable: 1.10.0 ... 1.8.5 (58 versions)
<p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of…
- CVE-2020-17048MEDIUMCVSS 4.2EG 4.2fixed in 1.11.232020-11-11
vulnerable: 1.10.0 ... 1.8.5 (59 versions)
Chakra Scripting Engine Memory Corruption Vulnerability
- CVE-2020-17054MEDIUMCVSS 4.2EG 4.2fixed in 1.11.232020-11-11
vulnerable: 1.10.0 ... 1.8.5 (59 versions)
Chakra Scripting Engine Memory Corruption Vulnerability
- CVE-2020-17131MEDIUMCVSS 4.2EG 4.2fixed in 1.11.242020-12-10
vulnerable: 1.10.0 ... 1.8.5 (60 versions)
Chakra Scripting Engine Memory Corruption Vulnerability
- CVE-2021-42279HIGHCVSS 7.5EG 7.52021-11-10
vulnerable: 1.10.0 ... 1.8.5 (61 versions)
Chakra Scripting Engine Memory Corruption Vulnerability
Check whether Microsoft.ChakraCore is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for Microsoft.ChakraCore CVEs against the assets you own.
Book a Demo →