6.8
CVSSv2

CVE-2018-4437

Published: 03/04/2019 Updated: 05/04/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple memory corruption issues have been found in WebKitGTK+ prior to 2.22.5, where processing maliciously crafted web content may lead to arbitrary code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

apple watchos

apple tvos

apple safari

apple itunes

apple icloud

Vendor Advisories

Several security issues were fixed in WebKitGTK+ ...
Multiple memory corruption issues have been found in WebKitGTK+ before 2225, where processing maliciously crafted web content may lead to arbitrary code execution ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2018-12-05-5 iTunes 1292 for Windows iTunes 1292 for Windows is now available and addresses the following: Safari Available for: Windows 7 and later Impact: Visiting a malicious website may lead to address bar spoofing Description: A logic issue was addressed with improved state manage ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2018-12-06-1 watchOS 512 watchOS 512 is now available and addresses the following: Airport Available for: Apple Watch Series 1 and later Impact: A malicious application may be able to elevate privileges Description: A type confusion issue was addressed with improved memory handling CV ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2018-12-05-3 tvOS 1211 tvOS 1211 is now available and addresses the following: Airport Available for: Apple TV 4K and Apple TV (4th generation) Impact: A malicious application may be able to elevate privileges Description: A type confusion issue was addressed with improved memory handl ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2018-12-05-6 iCloud for Windows 79 iCloud for Windows 79 is now available and addresses the following: Safari Available for: Windows 7 and later Impact: Visiting a malicious website may lead to address bar spoofing Description: A logic issue was addressed with improved state management ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2018-12-05-1 iOS 1211 iOS 1211 is now available and addresses the following: Airport Available for: iPhone 5s and later, iPad Air and later, and iPod touch 6th generation Impact: A malicious application may be able to elevate privileges Description: A type confusion issue was addressed ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2018-12-05-4 Safari 1202 Safari 1202 is now available and addresses the following: Safari Available for: macOS Sierra 10126, macOS High Sierra 10136, and macOS Mojave 10141 Impact: Visiting a malicious website may lead to address bar spoofing Description: A logic issue was addres ...

Github Repositories

CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript Engines (NDSS '19)

CodeAlchemist CodeAlchemist is a JavaScript engine fuzzer that improves classic grammar-based JS engine fuzzers by a novel test case generation algorithm, called semantics-aware assembly The details of the algorithm is in our paper, "CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript Engines", which appeared in NDSS 2019 This is a s