RHSA-2024:9636HighCVSS 8.8

Red Hat Security Advisory: webkit2gtk3 security update

Published
November 14, 2024
Last Modified
June 28, 2026

🔗 CVE IDs covered (21)

📋 Description

CVE-2023-42950 — webkit: heap use-after-free may lead to arbitrary code execution CVE-2023-43010 — webkitgtk: Processing maliciously crafted web content may lead to memory corruption CVE-2024-4558 — chromium-browser: Use after free in ANGLE CVE-2024-23271 — webkitgtk: A malicious website may cause unexpected cross-origin behavior CVE-2024-27820 — webkitgtk: Processing web content may lead to arbitrary code execution CVE-2024-27834 — webkit: pointer authentication bypass CVE-2024-27838 — webkitgtk: A maliciously crafted webpage may be able to fingerprint the user CVE-2024-27851 — webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution CVE-2024-27856 — webkitgtk: Processing a file may lead to unexpected app termination or arbitrary code execution CVE-2024-40779 — webkitgtk: webkit2gtk: Out-of-bounds read was addressed with improved bounds checking CVE-2024-40780 — webkitgtk: webkit2gtk: Out-of-bounds read was addressed with improved bounds checking CVE-2024-40782 — webkitgtk: webkit2gtk: Use-after-free was addressed with improved memory management CVE-2024-40789 — webkitgtk: webkit2gtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2024-40866 — webkitgtk: Visiting a malicious website may lead to address bar spoofing CVE-2024-44185 — webkitgtk: webkit2gtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2024-44187 — webkitgtk: A malicious website may exfiltrate data cross-origin CVE-2024-44244 — webkitgtk: webkit2gtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2024-44296 — webkitgtk: webkit2gtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced CVE-2024-54534 — webkit: Processing maliciously crafted web content may lead to memory corruption CVE-2024-54658 — webkitgtk: Processing web content may lead to a denial-of-service CVE-2025-43480 — webkitgtk: A malicious website may exfiltrate data cross-origin

🔗 References (17)