Gnome

Epiphany

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 23.01.2026 03:55:58
  • Zuletzt bearbeitet 26.01.2026 15:03:51

A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction. This design can be misused to exploit vulnerabilities within those handlers, making them appear remotely exploitable. T...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 20.02.2023 03:15:10
  • Zuletzt bearbeitet 18.03.2025 15:15:45

In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.

  • EPSS 0.15%
  • Veröffentlicht 20.04.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:59:17

In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 16.12.2021 03:15:10
  • Zuletzt bearbeitet 21.11.2024 06:31:55

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 16.12.2021 03:15:10
  • Zuletzt bearbeitet 21.11.2024 06:31:55

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 16.12.2021 03:15:10
  • Zuletzt bearbeitet 21.11.2024 06:31:55

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 16.12.2021 03:15:10
  • Zuletzt bearbeitet 21.11.2024 06:31:55

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.

Exploit
  • EPSS 2.45%
  • Veröffentlicht 14.01.2019 08:29:00
  • Zuletzt bearbeitet 21.11.2024 04:46:18

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 ...

Exploit
  • EPSS 0.89%
  • Veröffentlicht 07.06.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:25

libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write calls.

Exploit
  • EPSS 0.69%
  • Veröffentlicht 23.05.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:16

ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open ca...