VYPR

rpm package

almalinux/webkit2gtk3-jsc

pkg:rpm/almalinux/webkit2gtk3-jsc

Vulnerabilities (565)

  • CVE-2025-43431HigNov 4, 2025
    affected < 2.50.3-1.el8_10fixed 2.50.3-1.el8_10

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption.

  • CVE-2025-43430MedNov 4, 2025
    affected < 2.50.3-1.el8_10fixed 2.50.3-1.el8_10

    This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2025-43429MedNov 4, 2025
    affected < 2.50.3-1.el8_10fixed 2.50.3-1.el8_10

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpecte

  • CVE-2025-43427MedNov 4, 2025
    affected < 2.50.3-1.el8_10fixed 2.50.3-1.el8_10

    This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2025-43425MedNov 4, 2025
    affected < 2.50.3-1.el8_10fixed 2.50.3-1.el8_10

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2025-43421MedNov 4, 2025
    affected < 2.50.3-1.el8_10fixed 2.50.3-1.el8_10

    Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2025-43419HigNov 4, 2025
    affected < 2.50.3-1.el8_10fixed 2.50.3-1.el8_10

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to memory corruption.

  • CVE-2025-43392MedNov 4, 2025
    affected < 2.50.3-1.el8_10fixed 2.50.3-1.el8_10

    The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A website may exfiltrate image data cross-origin.

  • CVE-2025-10502HigSep 24, 2025
    affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10

    Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)

  • CVE-2025-43368MedSep 15, 2025
    affected < 2.50.0-1.el8_10fixed 2.50.0-1.el8_10

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.

  • CVE-2025-43356MedSep 15, 2025
    affected < 2.50.0-1.el8_10fixed 2.50.0-1.el8_10

    The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A website may be able to access sensor information without user consent.

  • CVE-2025-43343CriSep 15, 2025
    affected < 2.50.1-1.el8_10fixed 2.50.1-1.el8_10

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2025-43342CriSep 15, 2025
    affected < 2.50.0-1.el8_10fixed 2.50.0-1.el8_10

    A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2025-43272MedSep 15, 2025
    affected < 2.50.0-1.el8_10fixed 2.50.0-1.el8_10

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.

  • CVE-2025-9478HigAug 26, 2025
    affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10

    Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2025-8901HigAug 13, 2025
    affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10

    Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-43265MedJul 30, 2025
    affected < 2.48.5-1.el8_10fixed 2.48.5-1.el8_10

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose internal states of the app.

  • CVE-2025-43240MedJul 30, 2025
    affected < 2.48.5-1.el8_10fixed 2.48.5-1.el8_10

    A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.

  • CVE-2025-43227HigJul 30, 2025
    affected < 2.48.5-1.el8_10fixed 2.48.5-1.el8_10

    This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose sensitive user information.

  • CVE-2025-43216MedJul 30, 2025
    affected < 2.48.5-1.el8_10fixed 2.48.5-1.el8_10

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an unexpected Safar

Page 19 of 29