VYPR

Webkit

by Wpewebkit

CVEs (13)

  • CVE-2019-8720HigKEVMar 6, 2023
    risk 0.69cvss 8.8epss 0.02

    A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

  • CVE-2019-8375CriFeb 24, 2019
    risk 0.61cvss 9.8epss 0.16

    The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or…

  • CVE-2023-39928HigOct 6, 2023
    risk 0.57cvss 8.8epss 0.01

    A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger…

  • CVE-2020-13543HigDec 3, 2020
    risk 0.57cvss 8.8epss 0.03

    A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web page can trigger a use-after-free vulnerability which can lead to remote code execution. An attacker can get a user to visit a webpage to trigger this…

  • CVE-2018-4360HigApr 3, 2019
    risk 0.57cvss 8.8epss 0.02

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

  • CVE-2011-2335HigNov 12, 2019
    risk 0.49cvss 7.5epss 0.01

    A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function.

  • CVE-2016-9643HigMar 7, 2017
    risk 0.49cvss 7.5epss 0.03

    The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open parenthesis and dollar) followed by {-2,16} and a large number of +) (plus close parenthesis).

  • CVE-2011-2336MedNov 7, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControllerPrivate that signal when a hardware animation starts.

  • CVE-2011-2353MedNov 7, 2019
    risk 0.42cvss 6.5epss 0.01

    Use after free vulnerability in documentloader in WebKit in Google Chrome before Blink M13 in DocumentWriter::replaceDocument function.

  • CVE-2016-9642MedFeb 3, 2017
    risk 0.36cvss 5.5epss 0.01

    JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.

  • CVE-2010-1766Jul 22, 2010
    risk 0.00cvss epss 0.02

    Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have…

  • CVE-2009-3933Nov 12, 2009
    risk 0.00cvss epss 0.03

    WebKit before r50173, as used in Google Chrome before 3.0.195.32, allows remote attackers to cause a denial of service (CPU consumption) via a web page that calls the JavaScript setInterval method, which triggers an incompatibility between the WTF::currentTime and base::Time…

  • CVE-2008-6059Feb 5, 2009
    risk 0.00cvss epss 0.02

    xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls,…