Show filters
127 Total Results
Displaying 61-70 of 127
Sort by:
Attacker Value
Unknown

CVE-2019-6251

Disclosure Date: January 14, 2019 (last updated November 08, 2023)
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
0
Attacker Value
Unknown

CVE-2018-4210

Disclosure Date: January 11, 2019 (last updated November 08, 2023)
In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.
0
Attacker Value
Unknown

CVE-2018-4213

Disclosure Date: January 11, 2019 (last updated November 08, 2023)
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
0
Attacker Value
Unknown

CVE-2018-4208

Disclosure Date: January 11, 2019 (last updated November 08, 2023)
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
0
Attacker Value
Unknown

CVE-2018-4207

Disclosure Date: January 11, 2019 (last updated November 08, 2023)
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
0
Attacker Value
Unknown

CVE-2018-4212

Disclosure Date: January 11, 2019 (last updated November 08, 2023)
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
0
Attacker Value
Unknown

CVE-2018-12911

Disclosure Date: July 19, 2018 (last updated November 27, 2024)
WebKitGTK+ 2.20.3 has an off-by-one error, with a resultant out-of-bounds write, in the get_simple_globs functions in ThirdParty/xdgmime/src/xdgmimecache.c and ThirdParty/xdgmime/src/xdgmimeglob.c.
0
Attacker Value
Unknown

CVE-2018-12293

Disclosure Date: June 19, 2018 (last updated November 26, 2024)
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.
0
Attacker Value
Unknown

CVE-2018-11712

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections.
0
Attacker Value
Unknown

CVE-2018-11713

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.
0