WebKit records
11 published records for vendor webkit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 45.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-399 Resource Management Errors2
- CWE-416 Use After Free2
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2018-12294No exploit | WebCore/platform/graphics/texmap/TextureMapperLayer.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.2, is vulnerable to a use aftwebkit · webkitgtk\+ · CWE-416 | High8.8 | — | 2.4% | Jun 19, 2018 |
36Monitor | CVE-2020-9951No exploit | A use after free issue was addressed with improved memory management.apple · icloud · CWE-416 | High8.8 | — | 2.3% | Oct 16, 2020 |
36Monitor | CVE-2018-4209No exploit | In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windowapple · safari · CWE-20 | High8.8 | — | 2.1% | Jan 11, 2019 |
36Monitor | CVE-2020-9948No exploit | A type confusion issue was addressed with improved memory handling.apple · safari · CWE-843 | High8.8 | — | 1.7% | Oct 16, 2020 |
31Monitor | CVE-2016-9643No exploit | The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number webkit · webkit · CWE-400 | High7.5 | — | 3.1% | Mar 7, 2017 |
31Monitor | CVE-2010-1766No exploit | Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r5webkit · webkit · CWE-189 | High7.5 | — | 2.3% | Jul 22, 2010 |
28Monitor | CVE-2008-1590No exploit | JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which alapple · iphone · CWE-399 | Medium6.8 | — | 2.8% | Jul 14, 2008 |
28Monitor | CVE-2020-9952No exploit | An input validation issue was addressed with improved input validation.apple · icloud · CWE-79 | High7.1 | — | 1.5% | Oct 16, 2020 |
22Monitor | CVE-2016-9642No exploit | JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.webkit · webkit · CWE-125 | Medium5.5 | — | 1.3% | Feb 3, 2017 |
21Monitor | CVE-2009-3933No exploit | WebKit before r50173, as used in Google Chrome before 3.0.195.32, allows remote attackers to cause a denial of service (CPU consumption) viawebkit · webkit · CWE-399 | Medium5.0 | — | 3.1% | Nov 12, 2009 |
21Monitor | CVE-2008-6059No exploit | xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Setwebkit · webkit · CWE-264 | Medium5.0 | — | 1.9% | Feb 4, 2009 |
- CVE-2018-1229436Monitor
WebCore/platform/graphics/texmap/TextureMapperLayer.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.2, is vulnerable to a use aft
HighCVSS 8.8No exploitEPSS 2%webkit · webkitgtk\+Jun 19, 2018
- CVE-2020-995136Monitor
A use after free issue was addressed with improved memory management.
HighCVSS 8.8No exploitEPSS 2%apple · icloudOct 16, 2020
- CVE-2018-420936Monitor
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Window
HighCVSS 8.8No exploitEPSS 2%apple · safariJan 11, 2019
- CVE-2020-994836Monitor
A type confusion issue was addressed with improved memory handling.
HighCVSS 8.8No exploitEPSS 2%apple · safariOct 16, 2020
- CVE-2016-964331Monitor
The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number
HighCVSS 7.5No exploitEPSS 3%webkit · webkitMar 7, 2017
- CVE-2010-176631Monitor
Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r5
HighCVSS 7.5No exploitEPSS 2%webkit · webkitJul 22, 2010
- CVE-2008-159028Monitor
JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which al
MediumCVSS 6.8No exploitEPSS 3%apple · iphoneJul 14, 2008
- CVE-2020-995228Monitor
An input validation issue was addressed with improved input validation.
HighCVSS 7.1No exploitEPSS 1%apple · icloudOct 16, 2020
- CVE-2016-964222Monitor
JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.
MediumCVSS 5.5No exploitEPSS 1%webkit · webkitFeb 3, 2017
- CVE-2009-393321Monitor
WebKit before r50173, as used in Google Chrome before 3.0.195.32, allows remote attackers to cause a denial of service (CPU consumption) via
MediumCVSS 5.0No exploitEPSS 3%webkit · webkitNov 12, 2009
- CVE-2008-605921Monitor
xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set
MediumCVSS 5.0No exploitEPSS 2%webkit · webkitFeb 4, 2009