Debian Webkit2Gtk vulnerabilities
680 known vulnerabilities affecting debian/webkit2gtk.
Total CVEs
680
CISA KEV
38
actively exploited
Public exploits
102
Exploited in wild
32
Severity breakdown
CRITICAL14HIGH239MEDIUM150LOW277
Vulnerabilities
Page 10 of 34
CVE-2022-42867HIGHCVSS 8.8fixed in webkit2gtk 2.38.3-1 (bookworm)2022
CVE-2022-42867 [HIGH] CVE-2022-42867: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.3-1)
bullseye: resolved (fixed in 2.38.3-1~deb11u1)
forky: re
debian
CVE-2022-22628HIGHCVSS 8.8fixed in webkit2gtk 2.36.0-1 (bookworm)2022
CVE-2022-22628 [HIGH] CVE-2022-22628: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.36.0-1)
bullseye: resolved (fixed in 2.36.0-3~deb11u1)
forky: r
debian
CVE-2022-26717HIGHCVSS 8.8fixed in webkit2gtk 2.36.3-1 (bookworm)2022
CVE-2022-26717 [HIGH] CVE-2022-26717: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.36.3-1)
bullseye: resolved (fixed i
debian
CVE-2022-2294HIGHCVSS 8.8KEVfixed in chromium 103.0.5060.114-1 (bookworm)2022
CVE-2022-2294 [HIGH] CVE-2022-2294: chromium - Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed ...
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 103.0.5060.114-1)
bullseye: resolved (fixed in 103.0.5060.114-1~deb11u1)
forky: resolved (fixed in 103.0.5060.114-1)
sid: resolved (fixed in 103.0.5060.114-1)
trixie
debian
CVE-2022-26716HIGHCVSS 8.8fixed in webkit2gtk 2.36.3-1 (bookworm)2022
CVE-2022-26716 [HIGH] CVE-2022-26716: webkit2gtk - A memory corruption issue was addressed with improved state management. This iss...
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.36.3-1)
bullseye: resolved (fixed in 2.36.3-1~deb11u1)
forky:
debian
CVE-2022-32885HIGHCVSS 8.8fixed in webkit2gtk 2.40.1-1 (bookworm)2022
CVE-2022-32885 [HIGH] CVE-2022-32885: webkit2gtk - A memory corruption issue was addressed with improved validation. This issue is ...
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution
Scope: local
bookworm: resolved (fixed in 2.40.1-1)
bullseye: resolved (fixed in 2.40.1-1~deb11u1)
forky: resolved (fixed in 2.40.1-1)
s
debian
CVE-2022-22590HIGHCVSS 8.8fixed in webkit2gtk 2.34.5-1 (bookworm)2022
CVE-2022-22590 [HIGH] CVE-2022-22590: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.34.5-1)
bullseye: resolved (fixed in 2.34.6-1~deb11u1)
forky: r
debian
CVE-2022-46700HIGHCVSS 8.8fixed in webkit2gtk 2.38.3-1 (bookworm)2022
CVE-2022-46700 [HIGH] CVE-2022-46700: webkit2gtk - A memory corruption issue was addressed with improved input validation. This iss...
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.3-1)
bullseye: resolved (fixe
debian
CVE-2022-42856HIGHCVSS 8.8KEVfixed in webkit2gtk 2.38.3-1 (bookworm)2022
CVE-2022-42856 [HIGH] CVE-2022-42856: webkit2gtk - A type confusion issue was addressed with improved state handling. This issue is...
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released
debian
CVE-2022-42863HIGHCVSS 8.8fixed in webkit2gtk 2.38.0-1 (bookworm)2022
CVE-2022-42863 [HIGH] CVE-2022-42863: webkit2gtk - A memory corruption issue was addressed with improved state management. This iss...
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.0-1)
bullseye: resolved (fixed in 2.38.0-1~deb11u1)
forky:
debian
CVE-2022-46691HIGHCVSS 8.8fixed in webkit2gtk 2.38.1-1 (bookworm)2022
CVE-2022-46691 [HIGH] CVE-2022-46691: webkit2gtk - A memory consumption issue was addressed with improved memory handling. This iss...
A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.1-1)
bullseye: resolved (fixe
debian
CVE-2022-32886HIGHCVSS 8.8fixed in webkit2gtk 2.38.0-1 (bookworm)2022
CVE-2022-32886 [HIGH] CVE-2022-32886: webkit2gtk - A buffer overflow issue was addressed with improved memory handling. This issue ...
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.0-1)
bullseye: resolved (fixed in 2.38.0-1~deb11u1)
forky: resolved (fixed in 2.38.0-1)
sid: resolve
debian
CVE-2022-26700HIGHCVSS 8.8fixed in webkit2gtk 2.36.3-1 (bookworm)2022
CVE-2022-26700 [HIGH] CVE-2022-26700: webkit2gtk - A memory corruption issue was addressed with improved state management. This iss...
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to code execution.
Scope: local
bookworm: resolved (fixed in 2.36.3-1)
bullseye: resolved (fixed in 2.36.3-1~deb11u1)
forky: resolved
debian
CVE-2022-26719HIGHCVSS 8.8fixed in webkit2gtk 2.36.3-1 (bookworm)2022
CVE-2022-26719 [HIGH] CVE-2022-26719: webkit2gtk - A memory corruption issue was addressed with improved state management. This iss...
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.36.3-1)
bullseye: resolved (fixed in 2.36.3-1~deb11u1)
forky:
debian
CVE-2022-42823HIGHCVSS 8.8fixed in webkit2gtk 2.38.2-1 (bookworm)2022
CVE-2022-42823 [HIGH] CVE-2022-42823: webkit2gtk - A type confusion issue was addressed with improved memory handling. This issue i...
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.2-1)
bullseye: resolved (fixed in 2.38.2-1~deb11u1)
forky: resolved
debian
CVE-2022-42826HIGHCVSS 8.8fixed in webkit2gtk 2.38.4-1 (bookworm)2022
CVE-2022-42826 [HIGH] CVE-2022-42826: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13, iOS 16.1 and iPadOS 16, Safari 16.1. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.4-1)
bullseye: resolved (fixed in 2.38.4-2~deb11u1)
forky: resolved (fixed in 2.38.4-1)
s
debian
CVE-2022-32792HIGHCVSS 8.8fixed in webkit2gtk 2.36.6-1 (bookworm)2022
CVE-2022-32792 [HIGH] CVE-2022-32792: webkit2gtk - An out-of-bounds write issue was addressed with improved input validation. This ...
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.36.6-1)
bullseye: resolved (fixed in 2.36.6-1~deb11u1)
for
debian
CVE-2022-32893HIGHCVSS 8.8KEVfixed in webkit2gtk 2.36.7-1 (bookworm)2022
CVE-2022-32893 [HIGH] CVE-2022-32893: webkit2gtk - An out-of-bounds write issue was addressed with improved bounds checking. This i...
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2022-46699HIGHCVSS 8.8fixed in webkit2gtk 2.38.3-1 (bookworm)2022
CVE-2022-46699 [HIGH] CVE-2022-46699: webkit2gtk - A memory corruption issue was addressed with improved state management. This iss...
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.3-1)
bullseye: resolved (fixed in 2.38.3-1~deb11u1)
forky:
debian
CVE-2022-22624HIGHCVSS 8.8fixed in webkit2gtk 2.36.0-1 (bookworm)2022
CVE-2022-22624 [HIGH] CVE-2022-22624: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4, tvOS 15.4, Safari 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.36.0-1)
bullseye: resolved (fixed in 2.36.0-3~deb11u1)
forky: resolved (fixe
debian