8.8
CVSSv3

CVE-2018-4372

Published: 03/04/2019 Updated: 05/04/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple memory corruption issues have been found in WebKitGTK+ versions before 2.22.4, possibly leading to arbitrary code execution while parsing crafted web content.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple watchos

apple iphone os

apple safari

apple tvos

apple icloud

apple itunes

Vendor Advisories

Several security issues were fixed in WebKitGTK+ ...
Multiple memory corruption issues have been found in WebKitGTK+ versions prior to 2224, possibly leading to arbitrary code execution while parsing crafted web content ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2018-10-30-4 watchOS 51 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Apple Product Security ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2018-10-30-3 Safari 1201 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Apple Product Securit ...

Github Repositories

CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript Engines (NDSS '19)

CodeAlchemist CodeAlchemist is a JavaScript engine fuzzer that improves classic grammar-based JS engine fuzzers by a novel test case generation algorithm, called semantics-aware assembly The details of the algorithm is in our paper, "CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript Engines", which appeared in NDSS 2019 This is a s