8.8
CVE-2019-8720
- EPSS 1.54%
- Veröffentlicht 06.03.2023 23:15:10
- Zuletzt bearbeitet 07.10.2026 18:17:08
- Erkennungen
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wpewebkit ≫ Wpe Webkit Version < 2.26.0
Redhat ≫ Codeready Linux Builder Version 8.0
Redhat ≫ Codeready Linux Builder Eus Version 8.4
Redhat ≫ Codeready Linux Builder Eus Version 8.6
Redhat ≫ Codeready Linux Builder For Arm64 Eus Version 8.0
Redhat ≫ Codeready Linux Builder For Arm64 Eus Version 8.4
Redhat ≫ Codeready Linux Builder For Arm64 Eus Version 8.6
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Eus Version 8.0
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Eus Version 8.4
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Eus Version 8.6
Redhat ≫ Codeready Linux Builder For Power Little Endian Eus Version 8.0
Redhat ≫ Codeready Linux Builder For Power Little Endian Eus Version 8.4
Redhat ≫ Codeready Linux Builder For Power Little Endian Eus Version 8.6
Redhat ≫ Enterprise Linux Version 8.0 HwPlatform arm64
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux Eus Version 8.4 HwPlatform arm64
Redhat ≫ Enterprise Linux Eus Version 8.6
Redhat ≫ Enterprise Linux Eus Version 8.6 HwPlatform arm64
Redhat ≫ Enterprise Linux For Arm64 Eus Version 8.6
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 7.0
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 8.0
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.4
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.6
Redhat ≫ Enterprise Linux For Power Big Endian Version 7.0
Redhat ≫ Enterprise Linux For Power Little Endian Version 7.0
Redhat ≫ Enterprise Linux For Power Little Endian Version 8.0
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.4
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.6
Redhat ≫ Enterprise Linux For Scientific Computing Version 7.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 8.4
Redhat ≫ Enterprise Linux Server Aus Version 8.6
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 8.4
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 8.6
Redhat ≫ Enterprise Linux Server Tus Version 8.4
Redhat ≫ Enterprise Linux Server Tus Version 8.6
Redhat ≫ Enterprise Linux Workstation Version 7.0
23.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
WebKitGTK Memory Corruption Vulnerability
SchwachstelleWebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.54% | 0.719 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
https://bugzilla.redhat.com/show_bug.cgi?id=1876611
https://webkitgtk.org/security/WSA-2019-0005.html
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8720