CVE-2019-8720
KEV
🔴 Łataj teraz
Wykonanie złośliwego kodu w WebKit przez przetwarzanie złośliwych treści internetowych.
CVSS
8.8
EPSS
1.6%
Exploit
weaponized
Vendor
redhat
Opis źródłowy (NVD)
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.6% |
| Opublikowano (NVD) | 2023-03-06 23:15:10 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 18:17:08 UTC |
Referencje
- https://bugzilla.redhat.com/show_bug.cgi?id=1876611 ([email protected]) [Issue Tracking, Third Party Advisory]
- https://webkitgtk.org/security/WSA-2019-0005.html ([email protected]) [Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8720 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]