Wpewebkit / Wpe Webkit
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-43343 | webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash | CRITICAL | 9.8 | Sep 15, 2025 |
| CVE-2025-43342 | webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash | CRITICAL | 9.8 | Sep 15, 2025 |
| CVE-2025-31277 KEV | webkitgtk: Processing maliciously crafted web content may lead to memory corruption | HIGH | 8.8 | Jul 29, 2025 |
| CVE-2025-6558 KEV | angle: insufficient input validation can cause undefined behavior | HIGH | 8.8 | Jul 15, 2025 |
| CVE-2024-27834 | webkit: pointer authentication bypass | HIGH | 8.8 | May 13, 2024 |
| CVE-2024-23263 | webkit: processing malicious web content prevents Content Security Policy from being enforced | HIGH | 8.1 | Mar 8, 2024 |
| CVE-2024-23280 | webkit: maliciously crafted webpage may be able to fingerprint the user | HIGH | 7.5 | Mar 8, 2024 |
| CVE-2024-23254 | webkit: malicious website may exfiltrate audio data cross-origin | MEDIUM | 6.5 | Mar 8, 2024 |
| CVE-2024-23284 | webkit: processing maliciously crafted web content prevents Content Security Policy from being enforced | MEDIUM | 6.5 | Mar 8, 2024 |
| CVE-2023-42843 | webkit: visiting a malicious website may lead to address bar spoofing | HIGH | 7.5 | Feb 21, 2024 |
| CVE-2023-40397 | webkitgtk: arbitrary javascript code execution | CRITICAL | 9.8 | Sep 6, 2023 |
| CVE-2023-32370 | webkitgtk: content security policy blacklist failure | MEDIUM | 5.3 | Sep 6, 2023 |
| CVE-2023-28198 | webkitgtk: use after free vulnerability | HIGH | 8.8 | Aug 14, 2023 |
| CVE-2019-8720 KEV | webkitgtk: Multiple memory corruption issues leading to arbitrary code execution | HIGH | 8.8 | Mar 6, 2023 |
| CVE-2022-32893 KEV | webkitgtk: processing maliciously crafted web content may lead to arbitrary code execution | HIGH | 8.8 | Aug 24, 2022 |
| CVE-2022-2294 KEV | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… | HIGH | 8.8 | Jul 28, 2022 |
| CVE-2021-42762 | webkitgtk: limited sandbox escape via VFS syscalls | MEDIUM | 5.3 | Oct 20, 2021 |
| CVE-2021-30952 KEV | webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution | HIGH | 8.8 | Aug 24, 2021 |
| CVE-2020-13753 | webkitgtk: Improper access management to CLONE_NEWUSER and the TIOCSTI ioctl | CRITICAL | 10.0 | Jul 14, 2020 |
| CVE-2020-11793 | webkitgtk: use-after-free via crafted web content | HIGH | 8.8 | Apr 17, 2020 |
| CVE-2020-10018 | webkitgtk: Use-after-free issue in accessibility/AXObjectCache.cpp | CRITICAL | 9.8 | Mar 2, 2020 |
| CVE-2019-11070 | webkitgtk: HTTP proxy setting deanonymization information disclosure | MEDIUM | 6.5 | Apr 10, 2019 |
| CVE-2019-6251 | webkitgtk: processing maliciously crafted web content lead to URI spoofing | HIGH | 8.1 | Jan 14, 2019 |
| CVE-2018-12293 | The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to versi… | HIGH | 8.8 | Jun 19, 2018 |
Showing 1 to 24 of 24 CVEs