Show filters
127 Total Results
Displaying 51-60 of 127
Sort by:
Attacker Value
Unknown

CVE-2013-7324

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) allows remote attackers to trigger unexpectedly high sound volume via malicious javascript. NOTE: this WebKit-GTK behavior complies with existing W3C standards and existing practices for GNOME desktop integration.
Attacker Value
Unknown

CVE-2016-4761

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS
Attacker Value
Unknown

CVE-2019-8674

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
Attacker Value
Unknown

CVE-2019-8764

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.
Attacker Value
Unknown

CVE-2019-8625

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.
Attacker Value
Unknown

CVE-2019-8719

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.
Attacker Value
Unknown

CVE-2019-8813

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.
Attacker Value
Unknown

CVE-2019-11070

Disclosure Date: April 10, 2019 (last updated November 08, 2023)
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
0
Attacker Value
Unknown

CVE-2019-6234

Disclosure Date: March 05, 2019 (last updated November 27, 2024)
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.
0
Attacker Value
Unknown

CVE-2019-8375

Disclosure Date: February 24, 2019 (last updated November 27, 2024)
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).
0