webkitgtk kayıtları
webkitgtk üreticisine ait 132 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 15 · %11,4
- Silahlaştırılmış
- 17 · %12,9
- Pre-auth RCE
- 51
- Düzeltme kaydı olan
- %86,4
- Yayından KEV’e ortanca
- 4 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer34
- CWE-416 Use After Free27
- CWE-20 Improper Input Validation10
- CWE-787 Out-of-bounds Write7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
132 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
86Hemen | CVE-2022-2294Silahlaştırılmış | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption viagoogle · chrome · CWE-787 | Yüksek8,8 | KEV | %70,5 | 27 Tem 2022 |
72Bu hafta | CVE-2023-41993Silahlaştırılmış | The issue was addressed with improved checks.apple · ipados · CWE-754 | Yüksek8,8 | KEV | %24,3 | 21 Eyl 2023 |
72Bu hafta | CVE-2023-32439Silahlaştırılmış | A type confusion issue was addressed with improved checks.apple · safari · CWE-843 | Yüksek8,8 | KEV | %24,0 | 23 Haz 2023 |
71Bu hafta | CVE-2023-37450Silahlaştırılmış | The issue was addressed with improved checks.apple · safari | Yüksek8,8 | KEV | %19,0 | 26 Tem 2023 |
71Bu hafta | CVE-2021-1870Silahlaştırılmış | A logic issue was addressed with improved restrictions.apple · ipados | Kritik9,8 | KEV | %7,7 | 2 Nis 2021 |
69Bu hafta | CVE-2021-1789Silahlaştırılmış | A type confusion issue was addressed with improved state handling.apple · ipados · CWE-843 | Yüksek8,8 | KEV | %14,0 | 2 Nis 2021 |
69Bu hafta | CVE-2023-32373Silahlaştırılmış | A use-after-free issue was addressed with improved memory management.apple · safari · CWE-416 | Yüksek8,8 | KEV | %12,2 | 23 Haz 2023 |
68Bu hafta | CVE-2022-32893Silahlaştırılmış | An out-of-bounds write issue was addressed with improved bounds checking.apple · safari · CWE-787 | Yüksek8,8 | KEV | %9,9 | 24 Ağu 2022 |
68Bu hafta | CVE-2025-6558Silahlaştırılmış | Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentiallgoogle · chrome · CWE-20 | Yüksek8,8 | KEV | %9,6 | 15 Tem 2025 |
68Bu hafta | CVE-2023-42917Silahlaştırılmış | A memory corruption vulnerability was addressed with improved locking.apple · safari · CWE-787 | Yüksek8,8 | KEV | %9,3 | 30 Kas 2023 |
65Bu hafta | CVE-2025-31277Silahlaştırılmış | The issue was addressed with improved memory handling.apple · safari · CWE-119 | Yüksek8,8 | KEV | %1,6 | 29 Tem 2025 |
65Bu hafta | CVE-2019-8720Silahlaştırılmış | A vulnerability was found in WebKit.webkitgtk · webkitgtk · CWE-119 | Yüksek8,8 | KEV | %1,6 | 6 Mar 2023 |
63Bu hafta | CVE-2021-30952Silahlaştırılmış | An integer overflow was addressed with improved input validation.apple · safari · CWE-190 | Yüksek7,8 | KEV | %7,0 | 24 Ağu 2021 |
61Bu hafta | CVE-2023-42916Silahlaştırılmış | An out-of-bounds read was addressed with improved input validation.apple · safari · CWE-125 | Orta6,5 | KEV | %17,8 | 30 Kas 2023 |
60Bu hafta | CVE-2023-28204Silahlaştırılmış | An out-of-bounds read was addressed with improved input validation.apple · safari · CWE-125 | Orta6,5 | KEV | %14,3 | 23 Haz 2023 |
55Planlayın | CVE-2010-1807Kavram kanıtı | WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floapple · safari · CWE-20 | Kritik9,3 | — | %61,3 | 10 Eyl 2010 |
51Planlayın | CVE-2018-11646Silahlaştırılmış | webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKwebkitgtk · webkitgtk\+ | Yüksek7,5 | — | %68,6 | 1 Haz 2018 |
46Planlayın | CVE-2018-4162Silahlaştırılmış | An issue was discovered in certain Apple products.apple · safari · CWE-119 | Yüksek8,8 | — | %37,8 | 3 Nis 2018 |
44Planlayın | CVE-2019-8375Kavram kanıtı | The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent twebkitgtk · webkitgtk · CWE-119 | Kritik9,8 | — | %16,1 | 24 Şub 2019 |
41Planlayın | CVE-2010-3116İstismar yok | Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 5.0.375google · chrome · CWE-416 | Kritik10,0 | — | %3,7 | 24 Ağu 2010 |
41Planlayın | CVE-2020-13753İstismar yok | The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl.webkitgtk · webkitgtk · CWE-20 | Kritik10,0 | — | %3,3 | 14 Tem 2020 |
41Planlayın | CVE-2010-3113İstismar yok | Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents, which allows remote attackers to causegoogle · chrome · CWE-119 | Kritik10,0 | — | %2,9 | 24 Ağu 2010 |
41Planlayın | CVE-2010-3114İstismar yok | The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performingoogle · chrome | Kritik10,0 | — | %1,8 | 24 Ağu 2010 |
40Planlayın | CVE-2020-10018İstismar yok | WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-webkitgtk · webkitgtk · CWE-416 | Kritik9,8 | — | %5,0 | 2 Mar 2020 |
40Planlayın | CVE-2010-4197İstismar yok | Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remotgoogle · chrome · CWE-416 | Kritik9,8 | — | %2,3 | 5 Kas 2010 |
- CVE-2022-229486Hemen
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %70google · chrome27 Tem 2022
- CVE-2023-4199372Bu hafta
The issue was addressed with improved checks.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %24apple · ipados21 Eyl 2023
- CVE-2023-3243972Bu hafta
A type confusion issue was addressed with improved checks.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %24apple · safari23 Haz 2023
- CVE-2023-3745071Bu hafta
The issue was addressed with improved checks.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %19apple · safari26 Tem 2023
- CVE-2021-187071Bu hafta
A logic issue was addressed with improved restrictions.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %8apple · ipados2 Nis 2021
- CVE-2021-178969Bu hafta
A type confusion issue was addressed with improved state handling.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %14apple · ipados2 Nis 2021
- CVE-2023-3237369Bu hafta
A use-after-free issue was addressed with improved memory management.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %12apple · safari23 Haz 2023
- CVE-2022-3289368Bu hafta
An out-of-bounds write issue was addressed with improved bounds checking.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %10apple · safari24 Ağu 2022
- CVE-2025-655868Bu hafta
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentiall
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %10google · chrome15 Tem 2025
- CVE-2023-4291768Bu hafta
A memory corruption vulnerability was addressed with improved locking.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %9apple · safari30 Kas 2023
- CVE-2025-3127765Bu hafta
The issue was addressed with improved memory handling.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %2apple · safari29 Tem 2025
- CVE-2019-872065Bu hafta
A vulnerability was found in WebKit.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %2webkitgtk · webkitgtk6 Mar 2023
- CVE-2021-3095263Bu hafta
An integer overflow was addressed with improved input validation.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %7apple · safari24 Ağu 2021
- CVE-2023-4291661Bu hafta
An out-of-bounds read was addressed with improved input validation.
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %18apple · safari30 Kas 2023
- CVE-2023-2820460Bu hafta
An out-of-bounds read was addressed with improved input validation.
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %14apple · safari23 Haz 2023
- CVE-2010-180755Planlayın
WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate flo
KritikCVSS 9,3Kavram kanıtıEPSS %61apple · safari10 Eyl 2010
- CVE-2018-1164651Planlayın
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebK
YüksekCVSS 7,5SilahlaştırılmışEPSS %69webkitgtk · webkitgtk\+1 Haz 2018
- CVE-2018-416246Planlayın
An issue was discovered in certain Apple products.
YüksekCVSS 8,8SilahlaştırılmışEPSS %38apple · safari3 Nis 2018
- CVE-2019-837544Planlayın
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent t
KritikCVSS 9,8Kavram kanıtıEPSS %16webkitgtk · webkitgtk24 Şub 2019
- CVE-2010-311641Planlayın
Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 5.0.375
KritikCVSS 10,0İstismar yokEPSS %4google · chrome24 Ağu 2010
- CVE-2020-1375341Planlayın
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl.
KritikCVSS 10,0İstismar yokEPSS %3webkitgtk · webkitgtk14 Tem 2020
- CVE-2010-311341Planlayın
Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents, which allows remote attackers to cause
KritikCVSS 10,0İstismar yokEPSS %3google · chrome24 Ağu 2010
- CVE-2010-311441Planlayın
The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performin
KritikCVSS 10,0İstismar yokEPSS %2google · chrome24 Ağu 2010
- CVE-2020-1001840Planlayın
WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-
KritikCVSS 9,8İstismar yokEPSS %5webkitgtk · webkitgtk2 Mar 2020
- CVE-2010-419740Planlayın
Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remot
KritikCVSS 9,8İstismar yokEPSS %2google · chrome5 Kas 2010