Wpewebkit Wpe Webkit vulnerabilities
23 known vulnerabilities affecting wpewebkit/wpe_webkit.
Total CVEs
23
CISA KEV
5
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL5HIGH9MEDIUM9
Vulnerabilities
Page 2 of 2
CVE-2019-11070MEDIUMCVSS 5.3fixed in 2.24.12019-04-10
CVE-2019-11070 [MEDIUM] CWE-19 CVE-2019-11070: WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy sett
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
nvd
CVE-2019-6251HIGHCVSS 8.1fixed in 2.24.12019-01-14
CVE-2019-6251 [HIGH] CVE-2019-6251: WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
nvd
CVE-2018-12293HIGHCVSS 8.8PoCfixed in 2.20.12018-06-19
CVE-2018-12293 [HIGH] CWE-190 CVE-2018-12293: The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBuff
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.
nvd
← Previous2 / 2