CVE-2017-0236
high · 7.5A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, and CVE-2017-0238.
7.5
CVSS
31.6%
EPSS (exploit prob.)
98th
EPSS percentile
2017-05-12
Published
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | edge | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/98234
- http://www.securitytracker.com/id/1038431
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0236
- http://www.securityfocus.com/bid/98234
- http://www.securitytracker.com/id/1038431
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0236
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-0236