Search CVE reports


Toggle filters

121 – 130 of 1231 results


CVE-2023-27932

Medium priority

Some fixes available 4 of 20

This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, watchOS 9.4. Processing maliciously crafted web content may bypass Same Origin Policy.

5 affected packages

qtwebkit-opensource-src, qtwebkit-source, webkit2gtk, webkitgtk, wpewebkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebkit-opensource-src Ignored Ignored Ignored Ignored
qtwebkit-source Not in release Not in release Not in release Ignored
webkit2gtk Not affected Fixed Fixed Ignored
webkitgtk Not in release Not in release Not in release Ignored
wpewebkit Not in release Ignored Ignored Not in release
Show less packages

CVE-2022-32885

Medium priority

Some fixes available 4 of 8

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution

5 affected packages

qtwebkit-opensource-src, qtwebkit-source, webkit2gtk, webkitgtk, wpewebkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebkit-opensource-src Not affected Not affected Not affected
qtwebkit-source Not in release Not in release Not affected
webkit2gtk Fixed Fixed Vulnerable
webkitgtk Not in release Not in release Not affected
wpewebkit Not affected Not affected Not in release
Show less packages

CVE-2023-28205

Medium priority

Some fixes available 4 of 20

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted...

5 affected packages

qtwebkit-opensource-src, qtwebkit-source, webkit2gtk, webkitgtk, wpewebkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebkit-opensource-src Ignored Ignored Ignored Ignored
qtwebkit-source Not in release Not in release Not in release Ignored
webkit2gtk Not affected Fixed Fixed Ignored
webkitgtk Not in release Not in release Not in release Ignored
wpewebkit Not in release Ignored Ignored Not in release
Show less packages

CVE-2023-25363

Medium priority
Ignored

A use-after-free vulnerability in WebCore::RenderLayer::updateDescendantDependentFlags in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

1 affected package

webkitgtk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
webkitgtk Not in release Not in release Ignored
Show less packages

CVE-2023-25362

Medium priority
Ignored

A use-after-free vulnerability in WebCore::RenderLayer::repaintBlockSelectionGaps in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

1 affected package

webkitgtk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
webkitgtk Not in release Not in release Ignored
Show less packages

CVE-2023-25361

Medium priority
Ignored

A use-after-free vulnerability in WebCore::RenderLayer::setNextSibling in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

1 affected package

webkitgtk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
webkitgtk Not in release Not in release Ignored
Show less packages

CVE-2023-25360

Medium priority
Ignored

A use-after-free vulnerability in WebCore::RenderLayer::renderer in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

1 affected package

webkitgtk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
webkitgtk Not in release Not in release Ignored
Show less packages

CVE-2023-25358

Medium priority

Some fixes available 3 of 19

A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

5 affected packages

webkitgtk, qtwebkit-opensource-src, qtwebkit-source, webkit2gtk, wpewebkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
webkitgtk Not in release Not in release Not in release Ignored
qtwebkit-opensource-src Ignored Ignored Ignored Ignored
qtwebkit-source Not in release Not in release Not in release Ignored
webkit2gtk Not affected Fixed Fixed Ignored
wpewebkit Not in release Ignored Ignored Not in release
Show less packages

CVE-2022-46705

Medium priority

Some fixes available 5 of 20

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, Safari 16.2. Visiting a malicious website may lead to...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
webkitgtk Not in release Not in release Not in release Ignored
webkit2gtk Fixed Fixed Fixed Ignored
qtwebkit-source Not in release Not in release Not in release Ignored
qtwebkit-opensource-src Ignored Ignored Ignored Ignored
wpewebkit Not in release Ignored Ignored Not in release
Show less packages

CVE-2022-32891

Medium priority

Some fixes available 6 of 22

The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.

5 affected packages

qtwebkit-opensource-src, qtwebkit-source, webkit2gtk, webkitgtk, wpewebkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtwebkit-opensource-src Ignored Ignored Ignored Ignored
qtwebkit-source Not in release Not in release Not in release Ignored
webkit2gtk Fixed Fixed Fixed Ignored
webkitgtk Not in release Not in release Not in release Ignored
wpewebkit Not in release Ignored Ignored Not in release
Show less packages