Skip to content
Noroxi

WebKit records

11 published records for vendor webkit.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
45.5%
Median publish → KEV
No record has entered KEV

All records

11 records
  • WebCore/platform/graphics/texmap/TextureMapperLayer.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.2, is vulnerable to a use aft

    HighCVSS 8.8No exploitEPSS 2%

    webkit · webkitgtk\+Jun 19, 2018

  • CVE-2020-9951
    36Monitor

    A use after free issue was addressed with improved memory management.

    HighCVSS 8.8No exploitEPSS 2%

    apple · icloudOct 16, 2020

  • CVE-2018-4209
    36Monitor

    In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Window

    HighCVSS 8.8No exploitEPSS 2%

    apple · safariJan 11, 2019

  • CVE-2020-9948
    36Monitor

    A type confusion issue was addressed with improved memory handling.

    HighCVSS 8.8No exploitEPSS 2%

    apple · safariOct 16, 2020

  • CVE-2016-9643
    31Monitor

    The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number

    HighCVSS 7.5No exploitEPSS 3%

    webkit · webkitMar 7, 2017

  • CVE-2010-1766
    31Monitor

    Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r5

    HighCVSS 7.5No exploitEPSS 2%

    webkit · webkitJul 22, 2010

  • CVE-2008-1590
    28Monitor

    JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which al

    MediumCVSS 6.8No exploitEPSS 3%

    apple · iphoneJul 14, 2008

  • CVE-2020-9952
    28Monitor

    An input validation issue was addressed with improved input validation.

    HighCVSS 7.1No exploitEPSS 1%

    apple · icloudOct 16, 2020

  • CVE-2016-9642
    22Monitor

    JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.

    MediumCVSS 5.5No exploitEPSS 1%

    webkit · webkitFeb 3, 2017

  • CVE-2009-3933
    21Monitor

    WebKit before r50173, as used in Google Chrome before 3.0.195.32, allows remote attackers to cause a denial of service (CPU consumption) via

    MediumCVSS 5.0No exploitEPSS 3%

    webkit · webkitNov 12, 2009

  • CVE-2008-6059
    21Monitor

    xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set

    MediumCVSS 5.0No exploitEPSS 2%

    webkit · webkitFeb 4, 2009