Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37vm-m2gx-6h3h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

accessibility/AXObjectCache.cpp in WebKit, as used in WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4, allows a denial of service (application crash) because maintenance of the m_deferredFocusedNodeChange data structure mishandles removal.

accessibility/AXObjectCache.cpp in WebKit, as used in WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4, allows a denial of service (application crash) because maintenance of the m_deferredFocusedNodeChange data structure mishandles removal.

EPSS

Процентиль: 86%
0.03151
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-416

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.

CVSS3: 7.5
redhat
больше 5 лет назад

WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.

CVSS3: 9.8
nvd
больше 5 лет назад

WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.

CVSS3: 9.8
debian
больше 5 лет назад

WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the ...

CVSS3: 7.5
fstec
больше 5 лет назад

Уязвимость модулей отображения веб-страниц WebKitGTK и WPE WebKit, связанная с использованием памяти после ее освобождения, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 86%
0.03151
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-416