
We found results for “”
CVE-2018-8452
Good to know:

Date: September 12, 2018
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aka "Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge.
Language: C++
Severity Score
Related Resources (9)
Severity Score
Weakness Type (CWE)
Exposure of Sensitive Information to an Unauthorized Actor
CWE-200Top Fix

Upgrade Version
Upgrade to version BaristaLabs.BaristaCore.ChakraCore.win-x86 - 1.11.2;Microsoft.Azure.StreamAnalytics.CICD - 1.2.0;Microsoft.ChakraCore - 1.11.1;Microsoft.TypeScript.MSBuild - 3.2.0;BaristaLabs.BaristaCore.ChakraCore.win-x64 - 1.11.2;BaristaLabs.BaristaCore.ChakraCore.win-arm - 1.11.2;Microsoft.ChakraCore.vc140 - 1.11.1;Microsoft.TypeScript.Compiler - no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | NONE |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | NONE |
Availability (A): | NONE |
Additional information: |