Vulnerabilities > Webkitgtk > Webkitgtk > 2.31.91

DATE CVE VULNERABILITY TITLE RISK
2022-05-06 CVE-2022-30293 Out-of-bounds Write vulnerability in multiple products
In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
network
high complexity
webkitgtk debian CWE-787
7.5
2021-12-25 CVE-2021-45481 Memory Leak vulnerability in Webkitgtk
In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create, leading to a segmentation violation and application crash, a different vulnerability than CVE-2021-30889.
network
webkitgtk CWE-401
4.3
2021-12-25 CVE-2021-45482 Use After Free vulnerability in Webkitgtk
In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::ContainerNode::firstChild, a different vulnerability than CVE-2021-30889.
network
webkitgtk CWE-416
4.3
2021-12-25 CVE-2021-45483 Use After Free vulnerability in Webkitgtk
In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::Frame::page, a different vulnerability than CVE-2021-30889.
network
webkitgtk CWE-416
4.3
2021-10-20 CVE-2021-42762 BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace.
local
low complexity
webkitgtk wpewebkit fedoraproject debian
5.3