NuGet package intelligence

Microsoft.ChakraCore Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the NuGet package Microsoft.ChakraCore, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
3
Known exploited vulnerabilities affecting Microsoft.ChakraCore
In CISA KEV
3
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
Microsoft.ChakraCore KEVs with sensor-observed exploitation activity

Review Microsoft.ChakraCore exploitation against the versions you run

All three exploited Microsoft.ChakraCore vulnerabilities tracked here are also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested Microsoft.ChakraCore vulnerabilities

3 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2018-8298

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine...

In CISA 03 Mar 2022
CVE-2016-7200

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory...

In CISA 28 Mar 2022
CVE-2016-7201

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory...

In CISA 28 Mar 2022

Recurring weakness patterns

Access of Resource Using Incompatible Type ('Type Confusion') and Out-of-bounds Write account for mapped occurrences across this Microsoft.ChakraCore KEV portfolio.

Browse all KEVs →