Skip to main content

Vendor archive

webkit CVEs

Beta · best-effort

11 CVEs tagged to vendor webkit0 Critical, 7 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2018-12294

Published Jun 19, 2018

WebCore/platform/graphics/texmap/TextureMapperLayer.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.2, is vulnerable to a use after free for a WebCore::TextureMapperLay…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9643

Published Mar 7, 2017

The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open parenthesis and dollar) fol…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9642

Published Feb 3, 2017

JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1766

Published Jul 22, 2010

Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3933

Published Nov 12, 2009

WebKit before r50173, as used in Google Chrome before 3.0.195.32, allows remote attackers to cause a denial of service (CPU consumption) via a web page that calls the JavaScript s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6059

Published Feb 5, 2009

xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1