Show filters
127 Total Results
Displaying 61-70 of 127
Sort by:
Attacker Value
Unknown
CVE-2019-6251
Disclosure Date: January 14, 2019 (last updated November 08, 2023)
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
0
Attacker Value
Unknown
CVE-2018-4210
Disclosure Date: January 11, 2019 (last updated November 08, 2023)
In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.
0
Attacker Value
Unknown
CVE-2018-4213
Disclosure Date: January 11, 2019 (last updated November 08, 2023)
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
0
Attacker Value
Unknown
CVE-2018-4208
Disclosure Date: January 11, 2019 (last updated November 08, 2023)
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
0
Attacker Value
Unknown
CVE-2018-4207
Disclosure Date: January 11, 2019 (last updated November 08, 2023)
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
0
Attacker Value
Unknown
CVE-2018-4212
Disclosure Date: January 11, 2019 (last updated November 08, 2023)
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.
0
Attacker Value
Unknown
CVE-2018-12911
Disclosure Date: July 19, 2018 (last updated November 27, 2024)
WebKitGTK+ 2.20.3 has an off-by-one error, with a resultant out-of-bounds write, in the get_simple_globs functions in ThirdParty/xdgmime/src/xdgmimecache.c and ThirdParty/xdgmime/src/xdgmimeglob.c.
0
Attacker Value
Unknown
CVE-2018-12293
Disclosure Date: June 19, 2018 (last updated November 26, 2024)
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.
0
Attacker Value
Unknown
CVE-2018-11712
Disclosure Date: June 04, 2018 (last updated November 26, 2024)
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections.
0
Attacker Value
Unknown
CVE-2018-11713
Disclosure Date: June 04, 2018 (last updated November 26, 2024)
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.
0