Chakracore
Vendor:
First CVE: Aug 11, 2017 · Active for 8 years
255
Total CVEs
More Total CVEs than 100% of tracked products
42.5
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.8%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Chakracore over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 11, 2017
8 years ago
Most Recent CVE
Jul 18, 2023
1,105 days ago
CVE Severity & Scoring
Chakracore255 CVEs
9%
89%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (2.0%)
Network250 (98.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (6.3%)
High239 (93.7%)
Unknown0 (0.0%)
User Interaction
None9 (3.5%)
Unknown0 (0.0%)
Required246 (96.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None255 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (255 CVEs).
255 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8298HIGH A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This | Jul 11, 2018 | 7.5 | 94 | YES | YES |
CVE-2019-0539HIGH A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption | Jan 8, 2019 | 7.5 | 82 | NO | YES |
CVE-2019-0567HIGH A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption | Jan 8, 2019 | 7.5 | 78 | NO | YES |
CVE-2018-0777HIGH Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the s | Jan 4, 2018 | 7.5 | 78 | NO | YES |
CVE-2018-0776HIGH Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the s | Jan 4, 2018 | 7.5 | 78 | NO | YES |
CVE-2018-0769HIGH Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the s | Jan 4, 2018 | 7.5 | 78 | NO | YES |
CVE-2018-0758HIGH Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the s | Jan 4, 2018 | 7.5 | 78 | NO | YES |
CVE-2018-0770HIGH Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the s | Jan 4, 2018 | 7.5 | 77 | NO | YES |
CVE-2018-8291HIGH A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability. | Jul 11, 2018 | 7.5 | 74 | NO | YES |
CVE-2018-8229HIGH A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption | Jun 14, 2018 | 7.5 | 74 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (255 CVEs).
CISA KEV
2 CVEs
0.8% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
48 CVEs
18.8% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (255 CVEs).
Media Mentions
Signals from CVEs in this product scope (255 CVEs).
Top CNAs Publishing CVEs For Chakracore
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.12.0.0 | 1 | 7.5 | 2.4% | 0 | 0 |