Show filters
246 Total Results
Displaying 131-140 of 246
Sort by:
Attacker Value
Unknown

CVE-2020-9951

Disclosure Date: October 16, 2020 (last updated February 22, 2025)
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2020-9948

Disclosure Date: October 16, 2020 (last updated February 22, 2025)
A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2020-13753

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal's input buffer, similar to CVE-2017-5226.
Attacker Value
Unknown

CVE-2020-11793

Disclosure Date: April 17, 2020 (last updated February 21, 2025)
A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash).
Attacker Value
Unknown

CVE-2020-10018

Disclosure Date: March 02, 2020 (last updated February 21, 2025)
WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.
Attacker Value
Unknown

CVE-2020-3867

Disclosure Date: February 27, 2020 (last updated February 21, 2025)
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to universal cross site scripting.
Attacker Value
Unknown

CVE-2012-0828

Disclosure Date: February 21, 2020 (last updated February 21, 2025)
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).
Attacker Value
Unknown

CVE-2013-7324

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) allows remote attackers to trigger unexpectedly high sound volume via malicious javascript. NOTE: this WebKit-GTK behavior complies with existing W3C standards and existing practices for GNOME desktop integration.
Attacker Value
Unknown

CVE-2016-4761

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS
Attacker Value
Unknown

CVE-2019-8674

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.