VULNERABILITY INTELLIGENCE
CVE-2016-3377
CVSS score7.5 HIGH
EPSS probability15.88%
CISA KEVNot currently listed
Published2016-09-14
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3350.
Weakness classification
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer