{"id":"CVE-2017-8658","details":"A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka \"Scripting Engine Memory Corruption Vulnerability\".","aliases":["GHSA-8v2h-4jpm-3wfm"],"modified":"2026-08-27T08:13:28.718098Z","published":"2017-08-11T01:29:02.290Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/100036"},{"type":"FIX","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8658"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/chakra-core/ChakraCore","events":[{"introduced":"0"},{"last_affected":"e63dc6fe31768885a5feecbbc7e5d5a914decd8a"}],"database_specific":{"cpe":"cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.7.0"}],"source":"CPE_RANGE"}}],"versions":["v1.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8658.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/chakra-core/chakracore","events":[{"introduced":"0"},{"last_affected":"e63dc6fe31768885a5feecbbc7e5d5a914decd8a"}],"database_specific":{"cpe":"cpe:2.3:a:microsoft:chakracore:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.7.0"}],"source":"CPE_RANGE"}}],"versions":["v1.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8658.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}