Filtered by vendor Microsoft Subscriptions
Filtered by product Edge Subscriptions
Total 757 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-30616 2 Fedoraproject, Microsoft 3 Fedora, Edge, Edge Chromium 2024-11-21 8.8 High
Chromium: CVE-2021-30616 Use after free in Media
CVE-2021-30615 2 Fedoraproject, Microsoft 3 Fedora, Edge, Edge Chromium 2024-11-21 6.5 Medium
Chromium: CVE-2021-30615 Cross-origin data leak in Navigation
CVE-2021-30614 2 Fedoraproject, Microsoft 3 Fedora, Edge, Edge Chromium 2024-11-21 8.8 High
Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
CVE-2021-30613 2 Fedoraproject, Microsoft 3 Fedora, Edge, Edge Chromium 2024-11-21 8.8 High
Chromium: CVE-2021-30613 Use after free in Base internals
CVE-2021-30612 2 Fedoraproject, Microsoft 3 Fedora, Edge, Edge Chromium 2024-11-21 8.8 High
Chromium: CVE-2021-30612 Use after free in WebRTC
CVE-2021-30611 2 Fedoraproject, Microsoft 3 Fedora, Edge, Edge Chromium 2024-11-21 8.8 High
Chromium: CVE-2021-30611 Use after free in WebRTC
CVE-2021-30610 2 Fedoraproject, Microsoft 3 Fedora, Edge, Edge Chromium 2024-11-21 8.8 High
Chromium: CVE-2021-30610 Use after free in Extensions API
CVE-2021-30609 2 Fedoraproject, Microsoft 3 Fedora, Edge, Edge Chromium 2024-11-21 8.8 High
Chromium: CVE-2021-30609 Use after free in Sign-In
CVE-2021-30608 2 Fedoraproject, Microsoft 3 Fedora, Edge, Edge Chromium 2024-11-21 8.8 High
Chromium: CVE-2021-30608 Use after free in Web Share
CVE-2021-30607 2 Fedoraproject, Microsoft 3 Fedora, Edge, Edge Chromium 2024-11-21 8.8 High
Chromium: CVE-2021-30607 Use after free in Permissions
CVE-2021-30606 2 Fedoraproject, Microsoft 3 Fedora, Edge, Edge Chromium 2024-11-21 8.8 High
Chromium: CVE-2021-30606 Use after free in Blink
CVE-2021-26439 2 Google, Microsoft 2 Android, Edge 2024-11-21 4.6 Medium
Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2021-26436 1 Microsoft 2 Edge, Edge Chromium 2024-11-21 6.1 Medium
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2021-26411 1 Microsoft 16 Edge, Internet Explorer, Windows 10 1507 and 13 more 2024-11-21 8.8 High
Internet Explorer Memory Corruption Vulnerability
CVE-2021-24100 1 Microsoft 1 Edge 2024-11-21 5 Medium
Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2021-21157 4 Fedoraproject, Google, Linux and 1 more 5 Fedora, Chrome, Linux Kernel and 2 more 2024-11-21 8.8 High
Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-21141 2 Google, Microsoft 2 Chrome, Edge 2024-11-21 6.5 Medium
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy via a crafted HTML page.
CVE-2021-21140 2 Google, Microsoft 2 Chrome, Edge 2024-11-21 6.8 Medium
Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device.
CVE-2021-1705 1 Microsoft 4 Edge, Windows 10, Windows Server 2016 and 1 more 2024-11-21 4.2 Medium
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
CVE-2020-1569 1 Microsoft 3 Edge, Windows 10, Windows Server 2019 2024-11-21 7.8 High
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge, and then convince a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements by adding specially crafted content that could exploit the vulnerability. In all cases, however, an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically by way of enticement in an email or Instant Messenger message, or by getting them to open an attachment sent through email. The security update addresses the vulnerability by modifying how Microsoft Edge handles objects in memory.