Page 2 of 938 results (0.004 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

06 Feb 2025 — Microsoft Edge (Chromium-based) Spoofing Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Microsoft Edge displays a warning about hazardous downloads. A crafted file name can cause the warning message to be displayed incorrectly, misleading the user into believ... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21404 • CWE-449: The UI Performs the Wrong Action CWE-451: User Interface (UI) Misrepresentation of Critical Information •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

24 Jan 2025 — Microsoft Edge (Chromium-based) Spoofing Vulnerability User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21262 • CWE-451: User Interface (UI) Misrepresentation of Critical Information •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

17 Jan 2025 — Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21185 • CWE-284: Improper Access Control •

CVSS: 7.4EPSS: 0%CPEs: 1EXPL: 0

17 Jan 2025 — Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21399 • CWE-273: Improper Check for Dropped Privileges CWE-426: Untrusted Search Path •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

06 Dec 2024 — Microsoft Edge (Chromium-based) Spoofing Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Microsoft Edge prompts the user after a file is downloaded. A crafted file name can cause the true file extension to be hidden, misleading the user into believing that the... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49041 • CWE-449: The UI Performs the Wrong Action •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

22 Nov 2024 — Microsoft Edge (Chromium-based) Spoofing Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49054 • CWE-357: Insufficient UI Warning of Dangerous Operations •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

14 Nov 2024 — Microsoft Edge (Chromium-based) Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49025 • CWE-359: Exposure of Private Personal Information to an Unauthorized Actor •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

18 Oct 2024 — Microsoft Edge (Chromium-based) Spoofing Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43577 • CWE-449: The UI Performs the Wrong Action •

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

17 Oct 2024 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49023 • CWE-416: Use After Free •

CVSS: 9.7EPSS: 6%CPEs: 1EXPL: 0

17 Oct 2024 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43579 • CWE-122: Heap-based Buffer Overflow •