NuGet Package Vulnerabilities
Vulnerabilities associated with Microsoft.ChakraCore.
Packages
Clear package- Microsoft.ChakraCore247 vulnerabilities
- Magick.NET-Q16-AnyCPU163 vulnerabilities
- Magick.NET-Q16-HDRI-AnyCPU163 vulnerabilities
- Magick.NET-Q8-AnyCPU163 vulnerabilities
- Magick.NET-Q16-HDRI-x86162 vulnerabilities
- Magick.NET-Q16-x86161 vulnerabilities
- Magick.NET-Q8-x86161 vulnerabilities
- Magick.NET-Q16-HDRI-OpenMP-arm64159 vulnerabilities
- Magick.NET-Q16-HDRI-x64159 vulnerabilities
- Magick.NET-Q16-OpenMP-arm64159 vulnerabilities
- Magick.NET-Q16-OpenMP-x64159 vulnerabilities
- Magick.NET-Q16-arm64159 vulnerabilities
- Magick.NET-Q16-HDRI-arm64158 vulnerabilities
- Magick.NET-Q8-OpenMP-arm64158 vulnerabilities
- Magick.NET-Q8-arm64158 vulnerabilities
- Magick.NET-Q8-OpenMP-x64155 vulnerabilities
- Magick.NET-Q16-x64154 vulnerabilities
- Magick.NET-Q8-x64152 vulnerabilities
- Magick.NET-Q16-HDRI-OpenMP-x6495 vulnerabilities
- Magick.NET-Q16-OpenMP-x8667 vulnerabilities
- DotNetNuke.Core36 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.win-x6427 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.win-x8626 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.win-arm25 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.linux-x6424 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-42279MEDIUM | Chakra Scripting Engine Memory Corruption VulnerabilityChakra Scripting Engine and ChakraCore are vulnerable to memory corruption due to an out-of-bounds write. The Microsoft advisory for CVE-2021-42279 was modified in August 2022 to include Microsoft.ChakraCore as an affected product. CWE-787Nov 10, 2021 | CVSS4.2v3.1 | EPSS1.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17131MEDIUM | Chakra Scripting Engine Memory Corruption VulnerabilityChakra Scripting Engine Memory Corruption Vulnerability CWE-787Dec 9, 2020 | CVSS4.2v3.1 | EPSS1.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17054MEDIUM | Chakra Scripting Engine Memory Corruption VulnerabilityChakra Scripting Engine Memory Corruption Vulnerability This CVE ID is unique from CVE-2020-17048. CWE-787Nov 11, 2020 | CVSS4.2v3.1 | EPSS2.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17048MEDIUM | Chakra Scripting Engine Memory Corruption VulnerabilityChakra Scripting Engine Memory Corruption Vulnerability This CVE ID is unique from CVE-2020-17054. CWE-787Nov 11, 2020 | CVSS4.2v3.1 | EPSS1.65% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1180MEDIUM | Scripting Engine Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1057, CVE-2020-1172. CWE-787Sep 11, 2020 | CVSS4.2v3.1 | EPSS2.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1172MEDIUM | Scripting Engine Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1057, CVE-2020-1180. CWE-787Sep 11, 2020 | CVSS4.2v3.1 | EPSS2.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1057MEDIUM | Scripting Engine Memory Corruption VulnerabilityA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1172, CVE-2020-1180. | CVSS4.2v3.1 | EPSS2.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1073HIGH | ChakraCore RCE VulnerabilityA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. | CVSS8.1v3.1 | EPSS8.64% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1065HIGH | ChakraCore RCE VulnerabilityA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. | CVSS7.5v3.1 | EPSS7.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1037HIGH | ChakraCore Remote Code Execution VulnerabilityA remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. CWE-787May 21, 2020 | CVSS7.5v3.1 | EPSS7.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0969HIGH | ChakraCore RCE VulnerabilityA remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. | CVSS7.5v3.1 | EPSS13.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0970HIGH | ChakraCore Remote Code Execution VulnerabilityA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0968. CWE-787Apr 15, 2020 | CVSS7.5v3.1 | EPSS13.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0848HIGH | Out-of-bounds write in ChakraCoreA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833. CWE-787Mar 12, 2020 | CVSS7.5v3.1 | EPSS9.59% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0832HIGH | Out-of-bounds write in ChakraCoreA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0833, CVE-2020-0848. CWE-787Mar 12, 2020 | CVSS7.5v3.1 | EPSS8.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0833HIGH | Out-of-bounds write in ChakraCoreA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-0848. CWE-787Mar 12, 2020 | CVSS7.5v3.1 | EPSS8.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0831HIGH | Out-of-bounds Write in ChakraCoreA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0832, CVE-2020-0833, CVE-2020-0848. CWE-787Mar 12, 2020 | CVSS7.5v3.1 | EPSS8.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0830HIGH | Out-of-bounds write in ChakraCoreA remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833, CVE-2020-0848. CWE-787Mar 12, 2020 | CVSS7.5v3.1 | EPSS8.73% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0828HIGH | Out-of-bounds Write in ChakraCoreA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833, CVE-2020-0848. CWE-787Mar 12, 2020 | CVSS7.5v3.1 | EPSS8.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0829HIGH | Out-of-bounds write in ChakraCoreA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833, CVE-2020-0848. CWE-787Mar 12, 2020 | CVSS7.5v3.1 | EPSS8.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0827HIGH | Out-of-bounds write in ChakraCoreA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833, CVE-2020-0848. CWE-787Mar 12, 2020 | CVSS7.5v3.1 | EPSS13.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0826HIGH | Out-of-bounds write in ChakraCoreA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833, CVE-2020-0848. CWE-787Mar 12, 2020 | CVSS7.5v3.1 | EPSS8.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0825HIGH | Out-of-bounds write in ChakraCoreA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833, CVE-2020-0848. CWE-787Mar 12, 2020 | CVSS7.5v3.1 | EPSS13.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0823HIGH | Out-of-bounds write in ChakraCoreA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833, CVE-2020-0848. CWE-787Mar 12, 2020 | CVSS7.5v3.1 | EPSS8.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0812HIGH | ChakraCore RCE VulnerabilityA remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0811. | CVSS7.5v3.1 | EPSS7.87% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-0813HIGH | ChakraCore information disclosure vulnerabilityAn information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user’s computer or data.To exploit the vulnerability, an attacker must know the memory address of where the object was created.The update addresses the vulnerability by changing the way certain functions handle objects in memory., aka 'Scripting Engine Information Disclosure Vulnerability'. Mar 12, 2020 | CVSS7.5v3.1 | EPSS5.46% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |