VYPR
High severity8.8NVD Advisory· Published Jun 19, 2018· Updated Jun 17, 2026

CVE-2018-12293

CVE-2018-12293

Description

The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • Range: <2.20.1
  • cpe:2.3:a:webkitgtk:webkitgtk\+:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:webkitgtk:webkitgtk\+:*:*:*:*:*:*:*:*range: <2.20.3
    • (no CPE)range: <2.20.3
  • cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*range: <2.20.1
    • (no CPE)range: <2.20.1
  • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.