VULNERABILITY INTELLIGENCE
CVE-2016-3248
CVSS score8.8 HIGH
EPSS probability22.96%
CISA KEVNot currently listed
Published2016-07-13
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 9 through 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3259.
Weakness classification
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer