Debian Wpewebkit vulnerabilities
316 known vulnerabilities affecting debian/wpewebkit.
Total CVEs
316
CISA KEV
36
actively exploited
Public exploits
1
Exploited in wild
29
Severity breakdown
CRITICAL14HIGH166MEDIUM130LOW6
Vulnerabilities
Page 10 of 16
CVE-2022-22628HIGHCVSS 8.8fixed in webkit2gtk 2.36.0-1 (bookworm)2022
CVE-2022-22628 [HIGH] CVE-2022-22628: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.36.0-1)
bullseye: resolved (fixed in 2.36.0-3~deb11u1)
forky: r
debian
CVE-2022-26717HIGHCVSS 8.8fixed in webkit2gtk 2.36.3-1 (bookworm)2022
CVE-2022-26717 [HIGH] CVE-2022-26717: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.36.3-1)
bullseye: resolved (fixed i
debian
CVE-2022-2294HIGHCVSS 8.8KEVfixed in chromium 103.0.5060.114-1 (bookworm)2022
CVE-2022-2294 [HIGH] CVE-2022-2294: chromium - Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed ...
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 103.0.5060.114-1)
bullseye: resolved (fixed in 103.0.5060.114-1~deb11u1)
forky: resolved (fixed in 103.0.5060.114-1)
sid: resolved (fixed in 103.0.5060.114-1)
trixie
debian
CVE-2022-26716HIGHCVSS 8.8fixed in webkit2gtk 2.36.3-1 (bookworm)2022
CVE-2022-26716 [HIGH] CVE-2022-26716: webkit2gtk - A memory corruption issue was addressed with improved state management. This iss...
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.36.3-1)
bullseye: resolved (fixed in 2.36.3-1~deb11u1)
forky:
debian
CVE-2022-32885HIGHCVSS 8.8fixed in webkit2gtk 2.40.1-1 (bookworm)2022
CVE-2022-32885 [HIGH] CVE-2022-32885: webkit2gtk - A memory corruption issue was addressed with improved validation. This issue is ...
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution
Scope: local
bookworm: resolved (fixed in 2.40.1-1)
bullseye: resolved (fixed in 2.40.1-1~deb11u1)
forky: resolved (fixed in 2.40.1-1)
s
debian
CVE-2022-22590HIGHCVSS 8.8fixed in webkit2gtk 2.34.5-1 (bookworm)2022
CVE-2022-22590 [HIGH] CVE-2022-22590: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.34.5-1)
bullseye: resolved (fixed in 2.34.6-1~deb11u1)
forky: r
debian
CVE-2022-46700HIGHCVSS 8.8fixed in webkit2gtk 2.38.3-1 (bookworm)2022
CVE-2022-46700 [HIGH] CVE-2022-46700: webkit2gtk - A memory corruption issue was addressed with improved input validation. This iss...
A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.3-1)
bullseye: resolved (fixe
debian
CVE-2022-42856HIGHCVSS 8.8KEVfixed in webkit2gtk 2.38.3-1 (bookworm)2022
CVE-2022-42856 [HIGH] CVE-2022-42856: webkit2gtk - A type confusion issue was addressed with improved state handling. This issue is...
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released
debian
CVE-2022-42863HIGHCVSS 8.8fixed in webkit2gtk 2.38.0-1 (bookworm)2022
CVE-2022-42863 [HIGH] CVE-2022-42863: webkit2gtk - A memory corruption issue was addressed with improved state management. This iss...
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.0-1)
bullseye: resolved (fixed in 2.38.0-1~deb11u1)
forky:
debian
CVE-2022-46691HIGHCVSS 8.8fixed in webkit2gtk 2.38.1-1 (bookworm)2022
CVE-2022-46691 [HIGH] CVE-2022-46691: webkit2gtk - A memory consumption issue was addressed with improved memory handling. This iss...
A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.1-1)
bullseye: resolved (fixe
debian
CVE-2022-32886HIGHCVSS 8.8fixed in webkit2gtk 2.38.0-1 (bookworm)2022
CVE-2022-32886 [HIGH] CVE-2022-32886: webkit2gtk - A buffer overflow issue was addressed with improved memory handling. This issue ...
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.0-1)
bullseye: resolved (fixed in 2.38.0-1~deb11u1)
forky: resolved (fixed in 2.38.0-1)
sid: resolve
debian
CVE-2022-26700HIGHCVSS 8.8fixed in webkit2gtk 2.36.3-1 (bookworm)2022
CVE-2022-26700 [HIGH] CVE-2022-26700: webkit2gtk - A memory corruption issue was addressed with improved state management. This iss...
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to code execution.
Scope: local
bookworm: resolved (fixed in 2.36.3-1)
bullseye: resolved (fixed in 2.36.3-1~deb11u1)
forky: resolved
debian
CVE-2022-26719HIGHCVSS 8.8fixed in webkit2gtk 2.36.3-1 (bookworm)2022
CVE-2022-26719 [HIGH] CVE-2022-26719: webkit2gtk - A memory corruption issue was addressed with improved state management. This iss...
A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.36.3-1)
bullseye: resolved (fixed in 2.36.3-1~deb11u1)
forky:
debian
CVE-2022-42823HIGHCVSS 8.8fixed in webkit2gtk 2.38.2-1 (bookworm)2022
CVE-2022-42823 [HIGH] CVE-2022-42823: webkit2gtk - A type confusion issue was addressed with improved memory handling. This issue i...
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.2-1)
bullseye: resolved (fixed in 2.38.2-1~deb11u1)
forky: resolved
debian
CVE-2022-42826HIGHCVSS 8.8fixed in webkit2gtk 2.38.4-1 (bookworm)2022
CVE-2022-42826 [HIGH] CVE-2022-42826: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13, iOS 16.1 and iPadOS 16, Safari 16.1. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.4-1)
bullseye: resolved (fixed in 2.38.4-2~deb11u1)
forky: resolved (fixed in 2.38.4-1)
s
debian
CVE-2022-32792HIGHCVSS 8.8fixed in webkit2gtk 2.36.6-1 (bookworm)2022
CVE-2022-32792 [HIGH] CVE-2022-32792: webkit2gtk - An out-of-bounds write issue was addressed with improved input validation. This ...
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.36.6-1)
bullseye: resolved (fixed in 2.36.6-1~deb11u1)
for
debian
CVE-2022-32893HIGHCVSS 8.8KEVfixed in webkit2gtk 2.36.7-1 (bookworm)2022
CVE-2022-32893 [HIGH] CVE-2022-32893: webkit2gtk - An out-of-bounds write issue was addressed with improved bounds checking. This i...
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2022-46699HIGHCVSS 8.8fixed in webkit2gtk 2.38.3-1 (bookworm)2022
CVE-2022-46699 [HIGH] CVE-2022-46699: webkit2gtk - A memory corruption issue was addressed with improved state management. This iss...
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.38.3-1)
bullseye: resolved (fixed in 2.38.3-1~deb11u1)
forky:
debian
CVE-2022-22624HIGHCVSS 8.8fixed in webkit2gtk 2.36.0-1 (bookworm)2022
CVE-2022-22624 [HIGH] CVE-2022-22624: webkit2gtk - A use after free issue was addressed with improved memory management. This issue...
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4, tvOS 15.4, Safari 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.36.0-1)
bullseye: resolved (fixed in 2.36.0-3~deb11u1)
forky: resolved (fixe
debian
CVE-2022-30293HIGHCVSS 7.5fixed in webkit2gtk 2.36.1-1 (bookworm)2022
CVE-2022-30293 [HIGH] CVE-2022-30293: webkit2gtk - In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overf...
In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
Scope: local
bookworm: resolved (fixed in 2.36.1-1)
bullseye: resolved (fixed in 2.36.3-1~deb11u1)
forky: resolved (fixed in 2.36.1-1)
sid: resolved (fixed in 2.36.1-1)
tri
debian