185 exploited vulnerabilities in Webkit
- Vendors
- Apple, Canonical, Alt Linux, Suse, Xmlsoft, Astra Linux
- With known exploits
- 185
- Affected Apple Safari versions
- ≤ 10.0.3, 9.1.2, 9.1.1, 5.0.5, 1.0, 1.0.0, 1.0.0b1, 1.0.0b2, 1.0.1, 1.0.2, 1.0.3, 1.1, 1.1.0, 1.1.1, 1.2, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.3, 1.3.0, 1.3.1, 1.3.2, 2, 2.0, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 3, 3.0, 3.0.0, 3.0.0b, 3.0.1, 3.0.1b, 3.0.2, 3.0.2b, 3.0.3, 3.0.3b, 3.0.4, 17.0, 11.1.1, 2.0.4_419.3, 13.1.1, 9.0, 6.2.6, 7.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 8.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.8, 17.1.2, 10.1
- Affected Apple Iphone Os versions
- All versions
- Affected Apple Tvos versions
- ≤ 10.1.1, 9.2.2, 9.2.1, 17.0, 11.4, 13.4.5, 10.2
- Affected Apple Ipados versions
- < 17.0, 13.5, 15.8.1, 16.7.3, 17.1.2
- Affected Apple Macos versions
- < 14.0, 14.1.2
- Affected Apple Watchos versions
- < 10.0, 4.3.1, 6.2.5
- Affected Google Chrome versions
- ≤ 46.0.2490.86, 11.0.696.71, 7.0.517.44, 18.0.1025.168, 5.0.375.70
- Affected Apple Webkit versions
- = build_18794
Vulnerabilities with exploits
Highest CVSS first — 22 of these already have exploit code on Sploitus
CVE-2017-2468 4 exploits
Apple WebKit - Document::adoptNode Use-After-Free ExploitApple WebKit - 'Document::adoptNode' Use-After-Free
CVE-2017-2469 4 exploits
Apple WebKit - JSC::SymbolTableEntry::isWatchable Heap Buffer Overflow ExploitApple WebKit - 'JSC::SymbolTableEntry::isWatchable' Heap Buffer Overflow
CVE-2017-2446 8 exploits
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple SafariExploit for Exposure of Sensitive Information to an Unauthorized Actor in Microsoft
CVE-2016-4622 4 exploits
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple SafariExploit for Exposure of Sensitive Information to an Unauthorized Actor in Microsoft
CVE-2016-1857
CVE-2011-1774 11 exploits
CVE-2023-42875
CVE-2017-2447 3 exploits
Apple Safari - Out-of-Bounds Read when Calling Bound Function ExploitSafari Browser: Out-of-bounds read when calling bound function(CVE-2017-2447)
CVE-2018-4192 3 exploits
CVE-2017-2419 1 exploit
CVE-2015-6769 1 exploit
CVE-2011-1804 1 exploit
CVE-2010-4204
CVE-2010-4197
CVE-2007-0342 1 exploit
CVE-2006-3946
CVE-2020-9805
CVE-2009-1692 5 exploits
CVE-2015-5928
CVE-2015-3659
CVE-2015-3658
CVE-2015-5822
CVE-2015-5809
CVE-2015-5801
CVE-2015-5794
CVE-2015-3749
CVE-2015-3748
CVE-2015-3747
CVE-2015-3745
CVE-2015-3743
CVE-2015-3741
CVE-2015-3731
CVE-2012-1521
CVE-2010-4206
CVE-2010-1772
CVE-2008-0985 2 exploits
Google Android Web Browser - '.GIF' File Heap Buffer OverflowCore Security Technologies Advisory 2008.0124
CVE-2023-42916
CVE-2017-2493 2 exploits
WebKit: UXSS through HTMLObjectElement::updateWidget(CVE-2017-2493)WebKit HTMLObjectElement::updateWidget Universal XSS
CVE-2017-2371 3 exploits
Apple WebKit Pop-Up Blocker Bypass ExploitApple WebKit 10.0.2 - Cross-Origin or Sandboxed IFRAME Pop-up Blocker Bypass
CVE-2017-2367 4 exploits
Apple Webkit Named Property UXSSApple Webkit - Universal Cross-Site Scripting by Accessing a Named Property from an Unloaded Window
CVE-2017-2365 3 exploits
Apple WebKit Frame::setDocument UXSS ExploitApple WebKit 10.0.2 - 'Frame::setDocument' Universal Cross-Site Scripting
CVE-2017-2364 4 exploits
Apple WebKit Frame::setDocument UXSSApple WebKit 10.0.2(12602.3.12.0.1) - Frame::setDocument (1) Universal Cross-Site Scripting Exploit
CVE-2017-2363 3 exploits
Apple WebKit 10.0.2 - FrameLoader::clear Universal Cross-Site Scripting ExploitApple WebKit 10.0.2 - 'FrameLoader::clear' Universal Cross-Site Scripting
CVE-2017-2479 3 exploits
Apple WebKit / Safari 10.0.3 (12602.4.8) - Universal Cross-Site Scripting ExploitApple WebKit / Safari 10.0.3 (12602.4.8) - Universal Cross-Site Scripting via a Focus Event and a Link Element
CVE-2017-2480 4 exploits
Apple WebKit / Safari 10.0.3 (12602.4.8) - Synchronous Page Load Universal Cross-Site Scripting ExplApple WebKit / Safari 10.0.3 (12602.4.8) - Synchronous Page Load Universal Cross-Site Scripting
CVE-2017-2442 4 exploits
Apple WebKit JSCallbackData UXSSApple Webkit - JSCallbackData Universal Cross-Site Scripting Exploit
CVE-2016-1779
CVE-2021-1826
CVE-2018-6128
CVE-2019-8658