VULNERABILITY INTELLIGENCE
CVE-2016-3386
CVSS score7.5 HIGH
EPSS probability41.32%
CISA KEVNot currently listed
Published2016-10-14
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3389, CVE-2016-7190, and CVE-2016-7194.
Weakness classification
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer