Vulnerabilities
Vulnerable Software
Webkitgtk:  >> Webkitgtk  Security Vulnerabilities
A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.
CVSS Score
8.8
EPSS Score
0.014
Published
2023-10-06
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution.
CVSS Score
9.8
EPSS Score
0.014
Published
2023-09-06
A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. Content Security Policy to block domains with wildcards may fail.
CVSS Score
5.3
EPSS Score
0.006
Published
2023-09-06
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.
CVSS Score
8.8
EPSS Score
0.008
Published
2023-08-14
CVE-2019-8720
Known exploited
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
CVSS Score
8.8
EPSS Score
0.015
Published
2023-03-06
A use-after-free vulnerability in WebCore::RenderLayer::setNextSibling in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
CVSS Score
8.8
EPSS Score
0.01
Published
2023-03-02
A use-after-free vulnerability in WebCore::RenderLayer::repaintBlockSelectionGaps in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
CVSS Score
8.8
EPSS Score
0.01
Published
2023-03-02
A use-after-free vulnerability in WebCore::RenderLayer::updateDescendantDependentFlags in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
CVSS Score
8.8
EPSS Score
0.01
Published
2023-03-02
A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
CVSS Score
8.8
EPSS Score
0.011
Published
2023-03-02
A use-after-free vulnerability in WebCore::RenderLayer::renderer in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
CVSS Score
8.8
EPSS Score
0.01
Published
2023-03-02


Contact Us

Shodan ® - All rights reserved