Google Security Research
1,215 exploits
Active since May 2013
ChakraCore < 1.7.6 - Remote Code Execution via Memory Corruption
CVSS 7.5
Microsoft Edge - Information Disclosure via Scripting Engine Memory Handling
CVSS 5.3
Microsoft Edge - Remote Code Execution via Chakra JavaScript Engine Memory Corruption
CVSS 8.8
Microsoft DirectWrite / AFDKO - Use of Uninitialized Memory While Freeing Resources in var_loadavar
Microsoft Edge - Remote Code Execution via Chakra JavaScript Engine
CVSS 7.5
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
CVSS 8.8
Microsoft DirectWrite / AFDKO - Stack-Based Buffer Overflow in do_set_weight_vector_cube for Large nAxes
Microsoft Edge - Remote Code Execution via Chakra JavaScript Engine Memory Corruption
CVSS 7.5
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
CVSS 8.8
Windows 10 and Windows Server 2019 - Remote Code Execution in DirectWrite
CVSS 8.8
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
CVSS 8.8
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
CVSS 8.8
Microsoft DirectWrite / AFDKO - Out-of-Bounds Read in OpenType Font Handling Due to Undefined FontName Index
Microsoft Edge - Remote Code Execution via Scripting Engine Memory Corruption
CVSS 7.5
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
CVSS 8.8
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
CVSS 8.8
Microsoft DirectWrite / AFDKO - Interpreter Stack Underflow in OpenType Font Handling Due to Missing CHKUFLOW
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
CVSS 8.8
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
CVSS 8.8
Microsoft DirectWrite / AFDKO - Multiple Bugs in OpenType Font Handling Related to the _post_ Table
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow Due to Integer Overflow in readTTCDirectory
Windows 10 - Information Disclosure via DirectWrite Memory Handling
CVSS 6.5
Windows 10 and Windows Server 2016/2019 - Remote Code Execution in DirectWrite
CVSS 8.8
Microsoft DirectWrite / AFDKO - NULL Pointer Dereferences in OpenType Font Handling While Accessing Empty dynarrays
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readEncoding