VYPR

rpm package

almalinux/webkit2gtk3

pkg:rpm/almalinux/webkit2gtk3

Vulnerabilities (565)

  • CVE-2026-28859MedMar 25, 2026
    affected < 2.52.3-1.el8_10fixed 2.52.3-1.el8_10

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A malicious website may be able to process restricted web content outside the sandbox.

  • CVE-2026-28857MedMar 25, 2026
    affected < 2.52.3-1.el8_10fixed 2.52.3-1.el8_10

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2026-20691MedMar 25, 2026
    affected < 2.52.3-1.el8_10fixed 2.52.3-1.el8_10

    An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted webpage may be able to fingerprint the user.

  • CVE-2026-20665MedMar 25, 2026
    affected < 2.52.3-1.el8_10fixed 2.52.3-1.el8_10

    This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content Securit

  • CVE-2026-20664MedMar 25, 2026
    affected < 2.52.3-1.el8_10fixed 2.52.3-1.el8_10

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2026-4464HigMar 20, 2026
    affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10

    Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-4460HigMar 20, 2026
    affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10

    Out of bounds read in Skia in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-4452HigMar 20, 2026
    affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10

    Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-4448HigMar 20, 2026
    affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10

    Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-20643MedMar 17, 2026
    affected < 2.52.3-1.el8_10fixed 2.52.3-1.el8_10

    A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Proce

  • CVE-2026-3909HigKEVMar 13, 2026
    affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10

    Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-3931HigMar 11, 2026
    affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10

    Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-3538HigMar 4, 2026
    affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10

    Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-3536HigMar 4, 2026
    affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10

    Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-20676MedFeb 11, 2026
    affected < 2.52.3-1.el8_10fixed 2.52.3-1.el8_10

    This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through Safari web extensions.

  • CVE-2026-20652HigFeb 11, 2026
    affected < 2.52.3-1.el8_10fixed 2.52.3-1.el8_10

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker may be able to cause a denial-of-service.

  • CVE-2026-20644MedFeb 11, 2026
    affected < 2.52.3-1.el8_10fixed 2.52.3-1.el8_10

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2026-20636MedFeb 11, 2026
    affected < 2.52.3-1.el8_10fixed 2.52.3-1.el8_10

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2026-20635MedFeb 11, 2026
    affected < 2.52.3-1.el8_10fixed 2.52.3-1.el8_10

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing maliciously crafted web content may lead to an unexpected proces

  • CVE-2026-20608MedFeb 11, 2026
    affected < 2.52.3-1.el8_10fixed 2.52.3-1.el8_10

    This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.

Page 17 of 29