CVE-2016-0024 – microsoft.chakracore
Package
Manager: nuget
Name: microsoft.chakracore
Vulnerable Version: >=0 <1.2.0
Severity
Level: High
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.32396 pctl0.967
Details
ChakraCore RCE Vulnerability The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Scripting Engine Memory Corruption Vulnerability."
Metadata
Created: 2022-05-14T02:26:20Z
Modified: 2023-11-02T19:55:48Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-g77f-7wm9-rh6p/GHSA-g77f-7wm9-rh6p.json
CWE IDs: ["CWE-119"]
Alternative ID: GHSA-g77f-7wm9-rh6p
Finding: F316
Auto approve: 1