Debian Webkit2Gtk vulnerabilities

680 known vulnerabilities affecting debian/webkit2gtk.

Total CVEs
680
CISA KEV
38
actively exploited
Public exploits
102
Exploited in wild
32
Severity breakdown
CRITICAL14HIGH239MEDIUM150LOW277

Vulnerabilities

Page 9 of 34
CVE-2023-38600HIGHCVSS 8.8fixed in webkit2gtk 2.40.5-1~deb12u1 (bookworm)2023
CVE-2023-38600 [HIGH] CVE-2023-38600: webkit2gtk - The issue was addressed with improved checks. This issue is fixed in iOS 16.6 an... The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution. Scope: local bookworm: resolved (fixed in 2.40.5-1~deb12u1) bullseye: resolved (fixed in 2.40.5-1~deb11u1) forky: resolved (fixed in 2.40.5-1) sid: reso
debian
CVE-2023-28204MEDIUMCVSS 6.5KEVfixed in webkit2gtk 2.40.2-1~deb12u1 (bookworm)2023
CVE-2023-28204 [MEDIUM] CVE-2023-28204: webkit2gtk - An out-of-bounds read was addressed with improved input validation. This issue i... An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited. Scope: local bookworm:
debian
CVE-2023-42883MEDIUMCVSS 5.5fixed in webkit2gtk 2.42.4-1~deb12u1 (bookworm)2023
CVE-2023-42883 [MEDIUM] CVE-2023-42883: webkit2gtk - The issue was addressed with improved memory handling. This issue is fixed in Sa... The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead to a denial-of-service. Scope: local bookworm: resolved (fixed in 2.42.4-1~deb12u1) bullseye: resolved (fixed in 2.42.4-1~deb11u1) forky: resol
debian
CVE-2023-38133MEDIUMCVSS 6.5fixed in webkit2gtk 2.40.5-1~deb12u1 (bookworm)2023
CVE-2023-38133 [MEDIUM] CVE-2023-38133: webkit2gtk - The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 ... The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. Processing web content may disclose sensitive information. Scope: local bookworm: resolved (fixed in 2.40.5-1~deb12u1) bullseye: resolved (fixed in 2.40.5-1~deb11u1) forky: resolved
debian
CVE-2023-27954MEDIUMCVSS 6.5fixed in webkit2gtk 2.40.1-1 (bookworm)2023
CVE-2023-27954 [MEDIUM] CVE-2023-27954: webkit2gtk - The issue was addressed by removing origin information. This issue is fixed in m... The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, watchOS 9.4. A website may be able to track sensitive user information. Scope: local bookworm: resolved (fixed in 2.40.1-1) bullseye: resolved (fixed in 2.40.1-1~deb11u1) forky: resolv
debian
CVE-2023-42956MEDIUMCVSS 6.5fixed in webkit2gtk 2.44.1-1~deb12u1 (bookworm)2023
CVE-2023-42956 [MEDIUM] CVE-2023-42956: webkit2gtk - The issue was addressed with improved memory handling. This issue is fixed in Sa... The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web content may lead to a denial-of-service. Scope: local bookworm: resolved (fixed in 2.44.1-1~deb12u1) bullseye: resolved (fixed in 2.44.1-1~deb11u1) forky: resolved (fixed in 2.44.0-1) sid: resolved (fixed in 2.44
debian
CVE-2023-38599MEDIUMCVSS 6.5fixed in webkit2gtk 2.40.5-1~deb12u1 (bookworm)2023
CVE-2023-38599 [MEDIUM] CVE-2023-38599: webkit2gtk - A logic issue was addressed with improved state management. This issue is fixed ... A logic issue was addressed with improved state management. This issue is fixed in Safari 16.6, watchOS 9.6, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. A website may be able to track sensitive user information. Scope: local bookworm: resolved (fixed in 2.40.5-1~deb12u1) bullseye: resolved (fixed in 2.40.5-1~deb11u1) f
debian
CVE-2023-41983MEDIUMCVSS 6.5fixed in webkit2gtk 2.42.2-1~deb12u1 (bookworm)2023
CVE-2023-41983 [MEDIUM] CVE-2023-41983: webkit2gtk - The issue was addressed with improved memory handling. This issue is fixed in ma... The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing web content may lead to a denial-of-service. Scope: local bookworm: resolved (fixed in 2.42.2-1~deb12u1) bullseye: resolved (fixed in 2.42.2-1~deb11u1) forky: resolved (fixed in 2.42.2-1
debian
CVE-2023-32370MEDIUMCVSS 5.3fixed in webkit2gtk 2.40.1-1 (bookworm)2023
CVE-2023-32370 [MEDIUM] CVE-2023-32370: webkit2gtk - A logic issue was addressed with improved validation. This issue is fixed in mac... A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. Content Security Policy to block domains with wildcards may fail. Scope: local bookworm: resolved (fixed in 2.40.1-1) bullseye: resolved (fixed in 2.40.1-1~deb11u1) forky: resolved (fixed in 2.40.1-1) sid: resolved (fixed in 2.40.1-1) trixie: resolved (fixed in 2.40
debian
CVE-2023-42916MEDIUMCVSS 6.5KEVfixed in webkit2gtk 2.42.3-1~deb12u1 (bookworm)2023
CVE-2023-42916 [MEDIUM] CVE-2023-42916: webkit2gtk - An out-of-bounds read was addressed with improved input validation. This issue i... An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1. Scope: local bookworm: resolved (fixe
debian
CVE-2023-42843MEDIUMCVSS 4.3fixed in webkit2gtk 2.44.1-1~deb12u1 (bookworm)2023
CVE-2023-42843 [MEDIUM] CVE-2023-42843: webkit2gtk - An inconsistent user interface issue was addressed with improved state managemen... An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing. Scope: local bookworm: resolved (fixed in 2.44.1-1~deb12u1) bullseye: resolved (fixed in 2.44.1-1~deb11u1)
debian
CVE-2023-27932MEDIUMCVSS 5.5fixed in webkit2gtk 2.40.1-1 (bookworm)2023
CVE-2023-27932 [MEDIUM] CVE-2023-27932: webkit2gtk - This issue was addressed with improved state management. This issue is fixed in ... This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, watchOS 9.4. Processing maliciously crafted web content may bypass Same Origin Policy. Scope: local bookworm: resolved (fixed in 2.40.1-1) bullseye: resolved (fixed in 2.40.1-1~deb11u1) forky: resolved (fixed in 2
debian
CVE-2023-2203LOWCVSS 8.82023
CVE-2023-2203 [HIGH] CVE-2023-2203: webkit2gtk - A flaw was found in the WebKitGTK package. An improper input validation issue ma... A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red
debian
CVE-2023-32409LOWCVSS 8.6KEVfixed in webkit2gtk 2.42.0-1 (bookworm)2023
CVE-2023-32409 [HIGH] CVE-2023-32409: webkit2gtk - The issue was addressed with improved bounds checks. This issue is fixed in watc... The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited. Scope: local bookworm: resolved
debian
CVE-2022-22629HIGHCVSS 8.8fixed in webkit2gtk 2.36.0-1 (bookworm)2022
CVE-2022-22629 [HIGH] CVE-2022-22629: webkit2gtk - A buffer overflow issue was addressed with improved memory handling. This issue ... A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution. Scope: local bookworm: resolved (fixed in 2.36.0-1) bullseye: resolved (fixed in
debian
CVE-2022-22637HIGHCVSS 8.8fixed in webkit2gtk 2.34.4-1 (bookworm)2022
CVE-2022-22637 [HIGH] CVE-2022-22637: webkit2gtk - A logic issue was addressed with improved state management. This issue is fixed ... A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin behavior. Scope: local bookworm: resolved (fixed in 2.34.4-1) bullseye: resolved (fixed in 2.34.4-1~deb11u1) forky: resolved (fixed in 2.34.4-1)
debian
CVE-2022-32888HIGHCVSS 8.8fixed in webkit2gtk 2.38.0-1 (bookworm)2022
CVE-2022-32888 [HIGH] CVE-2022-32888: webkit2gtk - An out-of-bounds write issue was addressed with improved bounds checking. This i... An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, macOS Monterey 12.6, tvOS 16. Processing maliciously crafted web content may lead to arbitrary code execution. Scope: local bookworm: resolved (fixed in 2.38.0-1) bullseye: resolved (fi
debian
CVE-2022-26709HIGHCVSS 8.8fixed in webkit2gtk 2.36.3-1 (bookworm)2022
CVE-2022-26709 [HIGH] CVE-2022-26709: webkit2gtk - A use after free issue was addressed with improved memory management. This issue... A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution. Scope: local bookworm: resolved (fixed in 2.36.3-1) bullseye: resolved (fixed in 2.36.3-1~deb11u1) forky: r
debian
CVE-2022-48503HIGHCVSS 8.8KEVfixed in webkit2gtk 2.38.0-1 (bookworm)2022
CVE-2022-48503 [HIGH] CVE-2022-48503: webkit2gtk - The issue was addressed with improved bounds checks. This issue is fixed in tvOS... The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution. Scope: local bookworm: resolved (fixed in 2.38.0-1) bullseye: resolved (fixed in 2.38.0-1~deb11u1) forky: resolved (fixed in 2.38.0-1) sid: reso
debian
CVE-2022-22620HIGHCVSS 8.8KEVfixed in webkit2gtk 2.34.6-1 (bookworm)2022
CVE-2022-22620 [HIGH] CVE-2022-22620: webkit2gtk - A use after free issue was addressed with improved memory management. This issue... A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.. Scope: loc
debian