New issue
Advanced search Search tips
ListGrid
Loading...
  ID Type  Status  Priority  Milestone  Owner  Summary + Labels ...
  95 ---- Fixed ---- ---- forshaw@google.com IE11 ImmutableApplicationSettings EPM Privilege Escalation CCProjectZeroMembers  
  97 ---- Fixed ---- ---- forshaw@google.com IE11 EPM Parent Process DACL Sandbox Escape CCProjectZeroMembers  
  99 ---- Fixed ---- ---- forshaw@google.com IE11 AudioSrv RegistryKey EPM Privilege Escalation CCProjectZeroMembers  
  186 ---- Fixed ---- ---- forshaw@google.com IE11: CShdocvwBroker::EditWith EPM Sandbox Escape CCProjectZeroMembers  
  189 ---- Fixed ---- ---- forshaw@google.com IE11: CShdocvwBroker::MOTWCreateFileW EPM Local File Information Disclosure CCProjectZeroMembers  
  259 ---- Fixed ---- ---- mjurczyk@google.com Microsoft Internet Explorer DirectWrite memory disclosure via uninitialized transient array CCProjectZeroMembers  
  445 ---- WontFix ---- ---- cevans@google.com Placeholder: PoC for high-entropy ASLR bypass via MemoryProtector CCProjectZeroMembers  
  669 ---- WontFix ---- ---- mbarbella@google.com Microsoft Internet Explorer: READ in CAnimatablePropertyListElement::GetCurrentValues Reproducible ClusterFuzz CCProjectZeroMembers  
  677 ---- Fixed ---- ---- mbarbella@google.com Microsoft Internet Explorer: Read AV in MSHTML!Layout::LayoutBuilderDivider::BuildPageLayout CCProjectZeroMembers  
  691 ---- Fixed ---- ---- mbarbella@google.com Microsoft Internet Explorer: UAF in MSHTML!CSVGHelpers::SetAttributeStringAndPointer CCProjectZeroMembers  
  827 ---- Fixed ---- ---- mbarbella@google.com Microsoft Internet Explorer: Read AV in MSHTML!CMultiReadStreamLifetimeManager::ReleaseThreadStateInternal CCProjectZeroMembers  
  1076 ---- Fixed ---- ---- ifratric@google.com Microsoft IE: textarea.defaultValue memory disclosure CCProjectZeroMembers  
  1118 ---- Fixed ---- ---- ifratric@google.com Microsoft IE: Memory corruption in CStyleSheetArray::BuildListOfMatchedRules CCProjectZeroMembers  
  1233 ---- Fixed ---- ---- ifratric@google.com Microsoft IE: Memory curruption in CMarkup::DestroySplayTree CCProjectZeroMembers  
  1237 ---- Fixed ---- ---- ifratric@google.com Microsoft IE: Type confusion in VBScript arithmetic functions CCProjectZeroMembers  
  1340 ---- Fixed ---- ---- ifratric@google.com Microsoft IE11: use-after-free in jscript!JsErrorToString CCProjectZeroMembers