CVE-2019-8720High· 8.8▾ Abyssal⚠ Exploited in the wild0dayPoC availableA vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 48.4 · likelihood 0.3 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Federal remediation due Jun 13, 2022
Disclosed via NVD
Last analysed / modified upstream
1.6%
Added to the CISA catalog on May 23, 2022. Federal remediation due Jun 13, 2022. View catalog ↗
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
webkitgtk < 2.26.0wpe_webkit < 2.26.0codeready_linux_builder = 8.0codeready_linux_builder_eus = 8.4codeready_linux_builder_eus = 8.6codeready_linux_builder_for_arm64_eus = 8.0codeready_linux_builder_for_arm64_eus = 8.4codeready_linux_builder_for_arm64_eus = 8.6codeready_linux_builder_for_ibm_z_systems_eus = 8.0codeready_linux_builder_for_ibm_z_systems_eus = 8.4codeready_linux_builder_for_ibm_z_systems_eus = 8.6codeready_linux_builder_for_power_little_endian_eus = 8.0codeready_linux_builder_for_power_little_endian_eus = 8.4codeready_linux_builder_for_power_little_endian_eus = 8.6enterprise_linux = 8.0enterprise_linux_desktop = 7.0enterprise_linux_eus = 8.4enterprise_linux_eus = 8.6enterprise_linux_for_arm64_eus = 8.6enterprise_linux_for_ibm_z_systems = 7.0enterprise_linux_for_ibm_z_systems = 8.0enterprise_linux_for_ibm_z_systems_eus = 8.4enterprise_linux_for_ibm_z_systems_eus = 8.6enterprise_linux_for_power_big_endian = 7.0enterprise_linux_for_power_little_endian = 7.0enterprise_linux_for_power_little_endian = 8.0enterprise_linux_for_power_little_endian_eus = 8.4enterprise_linux_for_power_little_endian_eus = 8.6enterprise_linux_for_scientific_computing = 7.0enterprise_linux_server = 7.0enterprise_linux_server_aus = 8.4enterprise_linux_server_aus = 8.6enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.4enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.6enterprise_linux_server_tus = 8.4enterprise_linux_server_tus = 8.6enterprise_linux_server_update_services_for_sap_solutions = 8.4enterprise_linux_server_update_services_for_sap_solutions = 8.6enterprise_linux_workstation = 7.0Upgrade past the affected range:
webkitgtk 2.26.0wpe_webkit 2.26.0Connected by shared product, vendor, weakness, or advisory.
CVE-2015-2546High· 8.2The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privile…
CVE-2025-14174High· 8.8Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page
CVE-2020-0796Critical· 10.0A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
CVE-2021-31979High· 7.8Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-31277High· 8.8The issue was addressed with improved memory handling
CVE-2023-4966Critical· 9.4Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.