Debian Wpewebkit vulnerabilities
315 known vulnerabilities affecting debian/wpewebkit.
Total CVEs
315
CISA KEV
36
actively exploited
Public exploits
12
Exploited in wild
44
Severity breakdown
CRITICAL14HIGH166MEDIUM130LOW5
Vulnerabilities
Page 8 of 16
CVE-2025-24189P3HIGHCVSS 8.8fixed in webkit2gtk 2.48.0-1~deb12u1 (bookworm)2025
CVE-2025-24189 [HIGH] CVE-2025-24189: webkit2gtk - The issue was addressed with improved checks. This issue is fixed in Safari 18.3...
The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted web content may lead to memory corruption.
Scope: local
bookworm: resolved (fixed in 2.48.0-1~deb12u1)
bullseye: resolved (fixed in 2.48.0-1)
forky: resolved (fixed in
debian
CVE-2021-30846P3HIGHCVSS 7.8fixed in webkit2gtk 2.34.0-1 (bookworm)2021
CVE-2021-30846 [HIGH] CVE-2021-30846: webkit2gtk - A memory corruption issue was addressed with improved memory handling. This issu...
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.34.0-1)
bullseye: resolved (fixed in 2.34.1-1~deb11u1)
forky: resol
debian
CVE-2021-30984P3HIGHCVSS 7.5fixed in webkit2gtk 2.34.4-1 (bookworm)2021
CVE-2021-30984 [HIGH] CVE-2021-30984: webkit2gtk - A race condition was addressed with improved state handling. This issue is fixed...
A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.34.4-1)
bullseye: resolved (fixed in 2.34.4-1~deb11u1)
forky: resolved (
debian
CVE-2025-43342P3CRITICALCVSS 9.8fixed in webkit2gtk 2.50.1-1~deb12u1 (bookworm)2025
CVE-2025-43342 [CRITICAL] CVE-2025-43342: webkit2gtk - A correctness issue was addressed with improved checks. This issue is fixed in S...
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
Scope: local
bookworm: resolved (fixed in 2.50.1-1~deb12u1)
bullseye: resolved (fixed in
debian
CVE-2021-21779P3HIGHCVSS 8.8fixed in webkit2gtk 2.32.3-1 (bookworm)2021
CVE-2021-21779 [HIGH] CVE-2021-21779: webkit2gtk - A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handle...
A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiting a malicious web page to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.32.3-1)
bul
debian
CVE-2021-21806P3HIGHCVSS 8.8fixed in webkit2gtk 2.30.6-1 (bookworm)2021
CVE-2021-21806 [HIGH] CVE-2021-21806: webkit2gtk - An exploitable use-after-free vulnerability exists in WebKitGTK browser version ...
An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.3 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in remote code execution. The victim needs to visit a malicious web site to trigger the vulnerability.
Scope: local
bookworm: resolved (fixed in 2.30.6-1)
bullseye: resolved (fixed in 2.30.6-
debian
CVE-2023-39928P3HIGHCVSS 8.8fixed in webkit2gtk 2.42.1-1~deb12u1 (bookworm)2023
CVE-2023-39928 [HIGH] CVE-2023-39928: webkit2gtk - A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitG...
A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.42.1-1~deb12u1)
bullse
debian
CVE-2023-40451P3HIGHCVSS 8.8fixed in webkit2gtk 2.40.5-1~deb12u1 (bookworm)2023
CVE-2023-40451 [HIGH] CVE-2023-40451: webkit2gtk - This issue was addressed with improved iframe sandbox enforcement. This issue is...
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 2.40.5-1~deb12u1)
bullseye: resolved (fixed in 2.40.5-1~deb11u1)
forky: resolved (fixed in 2.40.5-1)
sid: resolved (fixed in 2.40.5-1)
trixie: re
debian
CVE-2025-66287P3HIGHCVSS 8.8fixed in webkit2gtk 2.50.3-1~deb12u1 (bookworm)2025
CVE-2025-66287 [HIGH] CVE-2025-66287: webkit2gtk - A flaw was found in WebKitGTK. Processing malicious web content can cause an une...
A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.
Scope: local
bookworm: resolved (fixed in 2.50.3-1~deb12u1)
bullseye: resolved (fixed in 2.50.3-1~deb11u1)
forky: resolved (fixed in 2.50.3-1)
sid: resolved (fixed in 2.50.3-1)
trixie: resolved (fixed in 2.50.3-1~deb13u1)
debian
CVE-2021-30849P3HIGHCVSS 7.8fixed in webkit2gtk 2.32.4-1 (bookworm)2021
CVE-2021-30849 [HIGH] CVE-2021-30849: webkit2gtk - Multiple memory corruption issues were addressed with improved memory handling. ...
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, watchOS 8, Safari 15, tvOS 15, iOS 15 and iPadOS 15, iTunes 12.12 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.32.4-1)
bullseye: resolved (fixe
debian
CVE-2020-13558P3HIGHCVSS 8.8fixed in webkit2gtk 2.30.5-1 (bookworm)2020
CVE-2020-13558 [HIGH] CVE-2020-13558: webkit2gtk - A code execution vulnerability exists in the AudioSourceProviderGStreamer functi...
A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A specially crafted web page can lead to a use after free.
Scope: local
bookworm: resolved (fixed in 2.30.5-1)
bullseye: resolved (fixed in 2.30.5-1)
forky: resolved (fixed in 2.30.5-1)
sid: resolved (fixed in 2.30.5-1)
trixie: resolved (fixed in 2.
debian
CVE-2023-25358P3HIGHCVSS 8.8fixed in webkit2gtk 2.38.0-1 (bookworm)2023
CVE-2023-25358 [HIGH] CVE-2023-25358: webkit2gtk - A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK be...
A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
Scope: local
bookworm: resolved (fixed in 2.38.0-1)
bullseye: resolved (fixed in 2.38.0-1~deb11u1)
forky: resolved (fixed in 2.38.0-1)
sid: resolved (fixed in 2.38.0-1)
trixie: resolved (fixed in 2.38.0-1)
debian
CVE-2023-25363P3HIGHCVSS 8.8fixed in webkit2gtk 2.38.0-1 (bookworm)2023
CVE-2023-25363 [HIGH] CVE-2023-25363: webkit2gtk - A use-after-free vulnerability in WebCore::RenderLayer::updateDescendantDependen...
A use-after-free vulnerability in WebCore::RenderLayer::updateDescendantDependentFlags in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
Scope: local
bookworm: resolved (fixed in 2.38.0-1)
bullseye: resolved (fixed in 2.38.0-1~deb11u1)
forky: resolved (fixed in 2.38.0-1)
sid: resolved (fixed in 2.38.0-1)
trixie: resolved (fixed in 2.38.0-1)
debian
CVE-2023-25362P3HIGHCVSS 8.8fixed in webkit2gtk 2.38.0-1 (bookworm)2023
CVE-2023-25362 [HIGH] CVE-2023-25362: webkit2gtk - A use-after-free vulnerability in WebCore::RenderLayer::repaintBlockSelectionGap...
A use-after-free vulnerability in WebCore::RenderLayer::repaintBlockSelectionGaps in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
Scope: local
bookworm: resolved (fixed in 2.38.0-1)
bullseye: resolved (fixed in 2.38.0-1~deb11u1)
forky: resolved (fixed in 2.38.0-1)
sid: resolved (fixed in 2.38.0-1)
trixie: resolved (fixed in 2.38.0-1)
debian
CVE-2023-25360P3HIGHCVSS 8.8fixed in webkit2gtk 2.38.0-1 (bookworm)2023
CVE-2023-25360 [HIGH] CVE-2023-25360: webkit2gtk - A use-after-free vulnerability in WebCore::RenderLayer::renderer in WebKitGTK be...
A use-after-free vulnerability in WebCore::RenderLayer::renderer in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
Scope: local
bookworm: resolved (fixed in 2.38.0-1)
bullseye: resolved (fixed in 2.38.0-1~deb11u1)
forky: resolved (fixed in 2.38.0-1)
sid: resolved (fixed in 2.38.0-1)
trixie: resolved (fixed in 2.38.0-1)
debian
CVE-2023-25361P3HIGHCVSS 8.8fixed in webkit2gtk 2.38.0-1 (bookworm)2023
CVE-2023-25361 [HIGH] CVE-2023-25361: webkit2gtk - A use-after-free vulnerability in WebCore::RenderLayer::setNextSibling in WebKit...
A use-after-free vulnerability in WebCore::RenderLayer::setNextSibling in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
Scope: local
bookworm: resolved (fixed in 2.38.0-1)
bullseye: resolved (fixed in 2.38.0-1~deb11u1)
forky: resolved (fixed in 2.38.0-1)
sid: resolved (fixed in 2.38.0-1)
trixie: resolved (fixed in 2.38.0-1)
debian
CVE-2021-30954P3HIGHCVSS 7.8fixed in webkit2gtk 2.34.4-1 (bookworm)2021
CVE-2021-30954 [HIGH] CVE-2021-30954: webkit2gtk - A type confusion issue was addressed with improved memory handling. This issue i...
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.34.4-1)
bullseye: resolved (fixed in 2.34.4-1~deb11u1)
forky: res
debian
CVE-2025-31223P3HIGHCVSS 8.0fixed in webkit2gtk 2.50.1-1~deb12u1 (bookworm)2025
CVE-2025-31223 [HIGH] CVE-2025-31223: webkit2gtk - The issue was addressed with improved checks. This issue is fixed in Safari 18.5...
The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.
Scope: local
bookworm: resolved (fixed in 2.50.1-1~deb12u1)
bullseye: resolved (fixed in 2.50.0-1)
forky: resolved (fixed in
debian
CVE-2025-43227P3HIGHCVSS 7.5fixed in webkit2gtk 2.48.5-1~deb12u1 (bookworm)2025
CVE-2025-43227 [HIGH] CVE-2025-43227: webkit2gtk - This issue was addressed through improved state management. This issue is fixed ...
This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose sensitive user information.
Scope: local
bookworm: resolved (fixed in 2.48.5-1~deb12u1)
bullseye: resolved (fixed in 2.48.5-1~de
debian
CVE-2023-42875P3HIGHCVSS 7.3fixed in webkit2gtk 2.42.1-1~deb12u1 (bookworm)2023
CVE-2023-42875 [HIGH] CVE-2023-42875: webkit2gtk - Processing web content may lead to arbitrary code execution. This issue is fixed...
Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. The issue was addressed with improved memory handling.
Scope: local
bookworm: resolved (fixed in 2.42.1-1~deb12u1)
bullseye: resolved (fixed in 2.42.1-1~deb11u1)
forky: resolved (fixed in 2.42.0-1)
sid: resolve
debian