Skip to content
Noroxi

wpewebkit records

24 published records for vendor wpewebkit.

Researcher profile

Entered KEV
6 · 25%
Weaponized
6 · 25%
Pre-auth RCE
5
With a fix record
100%
Median publish → KEV
18 days

All records

24 records
  • Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via

    HighCVSS 8.8KEVWeaponizedEPSS 70%

    google · chromeJul 27, 2022

  • CVE-2022-32893
    68This week

    An out-of-bounds write issue was addressed with improved bounds checking.

    HighCVSS 8.8KEVWeaponizedEPSS 10%

    apple · safariAug 24, 2022

  • CVE-2025-6558
    68This week

    Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentiall

    HighCVSS 8.8KEVWeaponizedEPSS 10%

    google · chromeJul 15, 2025

  • CVE-2025-31277
    65This week

    The issue was addressed with improved memory handling.

    HighCVSS 8.8KEVWeaponizedEPSS 2%

    apple · safariJul 29, 2025

  • CVE-2019-8720
    65This week

    A vulnerability was found in WebKit.

    HighCVSS 8.8KEVWeaponizedEPSS 2%

    webkitgtk · webkitgtkMar 6, 2023

  • CVE-2021-30952
    63This week

    An integer overflow was addressed with improved input validation.

    HighCVSS 7.8KEVWeaponizedEPSS 7%

    apple · safariAug 24, 2021

  • The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl.

    CriticalCVSS 10.0No exploitEPSS 3%

    webkitgtk · webkitgtkJul 14, 2020

  • WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-

    CriticalCVSS 9.8No exploitEPSS 5%

    webkitgtk · webkitgtkMar 2, 2020

  • The issue was addressed with improved checks.

    CriticalCVSS 9.8No exploitEPSS 2%

    apple · macosSep 6, 2023

  • The issue was addressed with improved memory handling.

    CriticalCVSS 9.8No exploitEPSS 1%

    apple · safariSep 15, 2025

  • A correctness issue was addressed with improved checks.

    CriticalCVSS 9.8No exploitEPSS 1%

    apple · safariSep 15, 2025

  • The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKit

    HighCVSS 8.8Proof of conceptEPSS 10%

    canonical · ubuntu linuxJun 19, 2018

  • A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers t

    HighCVSS 8.8No exploitEPSS 3%

    webkitgtk · webkitgtkApr 17, 2020

  • A use-after-free issue was addressed with improved memory management.

    HighCVSS 8.8No exploitEPSS 1%

    apple · ipadosAug 14, 2023

  • CVE-2019-6251
    33Monitor

    WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections.

    HighCVSS 8.1No exploitEPSS 4%

    webkitgtk · webkitgtkJan 14, 2019

  • A logic issue was addressed with improved validation.

    MediumCVSS 6.5No exploitEPSS 1%

    apple · safariMar 7, 2024

  • A logic issue was addressed with improved state management.

    MediumCVSS 6.5No exploitEPSS 1%

    apple · safariMar 7, 2024

  • An injection issue was addressed with improved validation.

    MediumCVSS 6.5No exploitEPSS 1%

    apple · safariMar 7, 2024

  • The issue was addressed with improved UI handling.

    MediumCVSS 6.5No exploitEPSS 1%

    apple · safariMar 7, 2024

  • WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (

    MediumCVSS 5.3No exploitEPSS 3%

    webkitgtk · webkitgtkApr 10, 2019

  • The issue was addressed with improved checks.

    MediumCVSS 5.5No exploitEPSS 1%

    apple · safariMay 14, 2024

  • A logic issue was addressed with improved validation.

    MediumCVSS 5.3No exploitEPSS 1%

    apple · macosSep 5, 2023

  • BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick ho

    MediumCVSS 5.3No exploitEPSS 1%

    webkitgtk · webkitgtkOct 20, 2021

  • An inconsistent user interface issue was addressed with improved state management.

    MediumCVSS 4.3No exploitEPSS 1%

    apple · safariFeb 21, 2024