CVE-2019-8720
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- WebKitGTK Memory Corruption Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 2% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-119
מוצרים מושפעים
webkitgtk: webkitgtk; wpewebkit: wpe webkit; redhat: codeready linux builder; redhat: codeready linux builder eus; redhat: codeready linux builder for arm64 eus; redhat: codeready linux builder for ibm z systems eus; redhat: codeready linux builder for power little endian eus; redhat: enterprise linux; redhat: enterprise linux desktop; redhat: enterprise linux eus; redhat: enterprise linux for arm64 eus; redhat: enterprise linux for ibm z systems; redhat: enterprise linux for ibm z systems eus; redhat: enterprise linux for power big endian; redhat: enterprise linux for power little endian
קישורים
- https://webkitgtk.org/security/WSA-2019-0005.html Vendor Advisory
- https://webkitgtk.org/security/WSA-2019-0005.html Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1876611 Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1876611 Issue TrackingThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource