• Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.

chakra

  1. 1

    Exploits Microsoft Edge Chakra 1.11.4 Type Confusion

    Microsoft Edge Chakra version 1.11.4 read permission via type confusion proof of concept exploit. View the full article
  2. dEEpEst

    Microsoft Edge Chakra JIT NewScObjectNoCtor / InitProto Type Confusion [CVE-2019-0567]

    Hidden content
  3. dEEpEst

    Microsoft Edge Chakra JIT Use-After-Free / Flag Issue [CVE-2019-0568]

    Hidden content
  4. dEEpEst

    Microsoft Edge Chakra InlineArrayPush Type Confusion [CVE-2018-8617]

    Hidden content
  5. 1

    Exploits Microsoft Edge Chakra InlineArrayPush Type Confusion

    Microsoft Edge suffers from a Chakra related type confusion vulnerability in InlineArrayPush. View the full article
  6. 1

    Exploits Microsoft Edge Chakra JIT Use-After-Free / Flag Issue

    In Microsoft Edge, the JsBuiltInEngineInterfaceExtensionObject::InjectJsBuiltInLibraryCode method is used to execute JsBuiltIn.js which initializes some builtin objects. Because it is essentially written in JavaScript, it needs to clear the disable-implicit-call flag before calling the...
  7. 1

    Exploits Microsoft Edge Chakra JIT NewScObjectNoCtor / InitProto Type Confusion

    Microsoft Edge has an issue where NewScObjectNoCtor and InitProto opcodes are treated as having no side effects, but actually they can have via the SetIsPrototype method of the type handler that can cause transition to a new type. This can lead to type confusion in the JITed code. View the full...
  8. 1

    Exploits Microsoft Edge Chakra OP_Memset Type Confusion

    Microsoft Edge suffers from a Chakra OP_Memset type confusion vulnerability. View the full article
  9. 1

    Exploits Microsoft Edge Chakra JIT Type Confusion Bug

    Microsoft Edge suffers from a Chakra JIT type confusion bug. View the full article
  10. 1

    Exploits Microsoft Edge Chakra JIT BailOutOnInvalidatedArrayHeadSegment Check Bypass

    Microsoft Edge suffers from a Chakra JIT BailOutOnInvalidatedArrayHeadSegment check bypass vulnerability. View the full article
  11. 1

    Exploits Microsoft Edge Chakra PathTypeHandlerBase::SetAttributesHelper Type Confusion

    Microsoft Edge Chakra suffers from a type confusion vulnerability with PathTypeHandlerBase::SetAttributesHelper. View the full article
  12. 1

    Exploits Microsoft Edge Chakra JIT localeCompare Type Confusion

    Microsoft Edge Chakra JIT suffers from a type confusion vulnerability in localeCompare. View the full article
  13. 1

    Exploits Microsoft Edge Chakra InitializeNumberFormat / InitializeDateTimeFormat Type Confusion

    The InitializeNumberFormat function in Intl.js is used to initialize an Intl.NumberFormat object, and InitializeDateTimeFormat is used for an Intl.DateTimeFormat object. There are two versions of each initializer. One is for WinGlob and the other is for ICU. The problem is that the versions for...
  14. 1

    Exploits Microsoft Edge Chakra JIT InlineArrayPush Type Confusion

    Microsoft Edge Chakra JIT suffers from a type confusion vulnerability with InlineArrayPush. View the full article
  15. 1

    Exploits Microsoft Edge Chakra DictionaryPropertyDescriptor::CopyFrom Failed Copy

    Microsoft Edge Chakra has an issue where DictionaryPropertyDescriptor::CopyFrom does not copy all fields. View the full article
  16. 1

    Exploits Microsoft Edge Chakra Parameter Scope Parsing Bug

    Microsoft Edge Chakra suffers from a parameter scope parsing bug. View the full article
  17. 1

    Exploits Microsoft Edge Chakra JIT ImplicitCallFlags Check Bypass

    Microsoft Edge Chakra JIT suffers from an ImplicitCallFlags check bypass vulnerability with Intl. View the full article
Back
Top