WebKit kayıtları
webkit üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %45,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-399 Resource Management Errors2
- CWE-416 Use After Free2
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2018-12294İstismar yok | WebCore/platform/graphics/texmap/TextureMapperLayer.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.2, is vulnerable to a use aftwebkit · webkitgtk\+ · CWE-416 | Yüksek8,8 | — | %2,4 | 19 Haz 2018 |
36İzleyin | CVE-2020-9951İstismar yok | A use after free issue was addressed with improved memory management.apple · icloud · CWE-416 | Yüksek8,8 | — | %2,3 | 16 Eki 2020 |
36İzleyin | CVE-2018-4209İstismar yok | In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windowapple · safari · CWE-20 | Yüksek8,8 | — | %2,1 | 11 Oca 2019 |
36İzleyin | CVE-2020-9948İstismar yok | A type confusion issue was addressed with improved memory handling.apple · safari · CWE-843 | Yüksek8,8 | — | %1,7 | 16 Eki 2020 |
31İzleyin | CVE-2016-9643İstismar yok | The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number webkit · webkit · CWE-400 | Yüksek7,5 | — | %3,1 | 7 Mar 2017 |
31İzleyin | CVE-2010-1766İstismar yok | Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r5webkit · webkit · CWE-189 | Yüksek7,5 | — | %2,3 | 22 Tem 2010 |
28İzleyin | CVE-2008-1590İstismar yok | JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which alapple · iphone · CWE-399 | Orta6,8 | — | %2,8 | 14 Tem 2008 |
28İzleyin | CVE-2020-9952İstismar yok | An input validation issue was addressed with improved input validation.apple · icloud · CWE-79 | Yüksek7,1 | — | %1,5 | 16 Eki 2020 |
22İzleyin | CVE-2016-9642İstismar yok | JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.webkit · webkit · CWE-125 | Orta5,5 | — | %1,3 | 3 Şub 2017 |
21İzleyin | CVE-2009-3933İstismar yok | WebKit before r50173, as used in Google Chrome before 3.0.195.32, allows remote attackers to cause a denial of service (CPU consumption) viawebkit · webkit · CWE-399 | Orta5,0 | — | %3,1 | 12 Kas 2009 |
21İzleyin | CVE-2008-6059İstismar yok | xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Setwebkit · webkit · CWE-264 | Orta5,0 | — | %1,9 | 4 Şub 2009 |
- CVE-2018-1229436İzleyin
WebCore/platform/graphics/texmap/TextureMapperLayer.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.2, is vulnerable to a use aft
YüksekCVSS 8,8İstismar yokEPSS %2webkit · webkitgtk\+19 Haz 2018
- CVE-2020-995136İzleyin
A use after free issue was addressed with improved memory management.
YüksekCVSS 8,8İstismar yokEPSS %2apple · icloud16 Eki 2020
- CVE-2018-420936İzleyin
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Window
YüksekCVSS 8,8İstismar yokEPSS %2apple · safari11 Oca 2019
- CVE-2020-994836İzleyin
A type confusion issue was addressed with improved memory handling.
YüksekCVSS 8,8İstismar yokEPSS %2apple · safari16 Eki 2020
- CVE-2016-964331İzleyin
The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number
YüksekCVSS 7,5İstismar yokEPSS %3webkit · webkit7 Mar 2017
- CVE-2010-176631İzleyin
Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r5
YüksekCVSS 7,5İstismar yokEPSS %2webkit · webkit22 Tem 2010
- CVE-2008-159028İzleyin
JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which al
OrtaCVSS 6,8İstismar yokEPSS %3apple · iphone14 Tem 2008
- CVE-2020-995228İzleyin
An input validation issue was addressed with improved input validation.
YüksekCVSS 7,1İstismar yokEPSS %1apple · icloud16 Eki 2020
- CVE-2016-964222İzleyin
JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.
OrtaCVSS 5,5İstismar yokEPSS %1webkit · webkit3 Şub 2017
- CVE-2009-393321İzleyin
WebKit before r50173, as used in Google Chrome before 3.0.195.32, allows remote attackers to cause a denial of service (CPU consumption) via
OrtaCVSS 5,0İstismar yokEPSS %3webkit · webkit12 Kas 2009
- CVE-2008-605921İzleyin
xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set
OrtaCVSS 5,0İstismar yokEPSS %2webkit · webkit4 Şub 2009