VYPR

rpm package

opensuse/webkit2gtk4&distro=openSUSE Leap 15.6

pkg:rpm/opensuse/webkit2gtk4&distro=openSUSE%20Leap%2015.6

Vulnerabilities (129)

  • CVE-2026-28861MedMar 25, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.

  • CVE-2026-20691Mar 25, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted webpage may be able to fingerprint the user.

  • CVE-2026-20664Mar 25, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2026-20665Mar 25, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content Securit

  • CVE-2026-28859Mar 25, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A malicious website may be able to process restricted web content outside the sandbox.

  • CVE-2026-28857Mar 25, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2026-28871Mar 25, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4. Visiting a maliciously crafted website may lead to a cross-site scripting attack.

  • CVE-2026-20643Mar 17, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Proce

  • CVE-2023-43010Mar 12, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

  • CVE-2026-20676MedFeb 11, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through Safari web extensions.

  • CVE-2026-20652HigFeb 11, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker may be able to cause a denial-of-service.

  • CVE-2026-20644MedFeb 11, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2026-20636MedFeb 11, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2026-20635MedFeb 11, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing maliciously crafted web content may lead to an unexpected proces

  • CVE-2026-20608MedFeb 11, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2025-46299MedJan 9, 2026
    affected < 2.52.1-150600.12.63.1fixed 2.52.1-150600.12.63.1

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app.

  • CVE-2025-43536MedDec 17, 2025
    affected < 2.50.4-150600.12.54.1fixed 2.50.4-150600.12.54.1

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2025-43531LowDec 17, 2025
    affected < 2.50.4-150600.12.54.1fixed 2.50.4-150600.12.54.1

    A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected

  • CVE-2025-43529HigKEVDec 17, 2025
    affected < 2.50.4-150600.12.54.1fixed 2.50.4-150600.12.54.1

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbit

  • CVE-2025-43535Dec 17, 2025
    affected < 2.50.4-150600.12.54.1fixed 2.50.4-150600.12.54.1

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

Page 1 of 7

VYPR — Vulnerability Intelligence