185 exploited vulnerabilities in Webkit
- Vendors
- Apple, Suse, Canonical, Alt Linux, Google, Red Hat
- With known exploits
- 185
- Affected Apple Safari versions
- All versions
- Affected Apple Iphone Os versions
- ≤ 10.3.3, 10.3.1, 10.3.2, 10.3, 10.2.1, 8.3, 8.4.1, 3.0, 3.1, 3.1.2, 3.1.3, 3.2, 3.2.1, 3.2.2, 4.0, 4.0.1, 4.0.2, 4.1, 4.2.1, 4.2.5, 4.2.8, 4.3.0, 4.3.1, 4.3.2, 4.3.3, 4.3.5
- Affected Apple Tvos versions
- ≤ 10.2.2, 10.2.1, 10.2, 10.1.1
- Affected Apple Itunes versions
- ≤ 12.6.1
- Affected Google Blink versions
- < m12
- Affected Apple Webkit versions
- All versions
- Affected Google Chrome versions
- < 11.0.696.43, 8.0.552.224, 4.0.249.78, 0.2.149.27, 0.2.149.29, 0.2.149.30, 0.2.152.1, 0.2.153.1, 0.3.154.0, 0.3.154.3, 0.4.154.18, 0.4.154.22, 0.4.154.31, 0.4.154.33, 1.0.154.36, 1.0.154.39, 1.0.154.42, 1.0.154.43, 1.0.154.46, 1.0.154.48, 1.0.154.52, 1.0.154.53, 1.0.154.59, 1.0.154.65, 2.0.156.1, 2.0.157.0, 2.0.157.2, 2.0.158.0, 2.0.159.0, 2.0.169.0, 2.0.169.1, 2.0.170.0, 2.0.172, 2.0.172.2, 2.0.172.8, 2.0.172.27, 2.0.172.28, 2.0.172.30, 2.0.172.31, 2.0.172.33, 2.0.172.37, 2.0.172.38, 46.0.2490.86, 47.0.2526.73, 22.0.1229.96, 22.0.1229.0, 22.0.1229.1, 22.0.1229.2, 22.0.1229.3, 22.0.1229.4, 22.0.1229.6, 22.0.1229.7, 22.0.1229.8, 22.0.1229.9, 22.0.1229.10, 22.0.1229.11, 22.0.1229.12, 22.0.1229.14, 22.0.1229.16, 22.0.1229.17, 22.0.1229.18, 22.0.1229.20, 22.0.1229.21, 22.0.1229.22, 22.0.1229.23, 22.0.1229.24, 22.0.1229.25, 22.0.1229.26, 22.0.1229.27, 22.0.1229.28, 22.0.1229.29, 22.0.1229.31, 22.0.1229.32, 22.0.1229.33, 22.0.1229.35, 22.0.1229.36, 22.0.1229.37, 22.0.1229.39, 22.0.1229.48, 22.0.1229.49, 22.0.1229.50, 22.0.1229.51, 22.0.1229.52, 11.0.672.2, 4.1.249.1035, 0.1.38.1, 0.1.38.2, 0.1.38.4, 0.1.40.1, 0.1.42.2, 0.1.42.3, 1.0.154.64, 3.0.182.2, 3.0.190.2, 3.0.195.25, 3.0.195.27, 3.0.195.33, 3.0.195.36, 3.0.195.37, 3.0.195.38, 4.0.212.0, 4.0.212.1, 4.0.221.8, 4.0.222.0, 4.0.222.1, 4.0.222.5, 4.0.222.12, 4.0.223.0, 4.0.223.1, 4.0.223.2
- Affected Webkitgtk versions
- < 1.2.6
Vulnerabilities with exploits
Highest CVSS first — 19 of these already have exploit code on Sploitus
CVE-2017-7089 6 exploits
WebKitGTK+ Code Execution / Cookie Handling / Memory Corruption VulnerabilitiesApple Safari uxss(CVE-2017-7089)
CVE-2017-7038
CVE-2017-2528 4 exploits
WebKit: UXSS: CachedFrame doesn't detach openers(CVE-2017-2528)WebKit CachedFrame Universal Cross Site Scripting Vulnerability
CVE-2017-2510 4 exploits
WebKit enqueuePageshowEvent / enqueuePopstateEvent Universal XSS(CVE-2017-2510)WebKit - enqueuePageshowEvent and enqueuePopstateEvent Universal Cross-Site Scripting Exploit
CVE-2017-2508 3 exploits
WebKit: UXSS via ContainerNode::parserInsertBefore(CVE-2017-2508)WebKit - ContainerNode::parserInsertBefore Universal Cross-Site Scripting Exploit
CVE-2017-2504 4 exploits
WebKit: UXSS via Editor::Command::execute(CVE-2017-2504)Apple WebKit / Safari 10.0.3(12602.4.8) - Editor::Command::execute Universal Cross-Site Scripting Ex
CVE-2017-2475
CVE-2017-2445 4 exploits
Apple WebKit disconnectSubframes UXSSApple WebKit 10.0.2(12602.3.12.0.1) - disconnectSubframes Universal Cross-Site Scripting Exploit
CVE-2017-7064 4 exploits
WebKit: JSC: JSArray::appendMemcpy uninitialized memory copy(CVE-2017-7064)WebKit JSC JSArray::appendMemcpy Uninitialized Memory Copy Vulnerability
CVE-2011-2335
CVE-2015-3752
CVE-2011-4692 1 exploit
CVE-2011-1691
CVE-2010-4577 4 exploits
CVE-2010-3804 2 exploits
WebKit - Insufficient Entropy Random Number Generator (1)WebKit - Insufficient Entropy Random Number Generator (2)
CVE-2010-1029 2 exploits
iPhone - 'WebCore::CSSSelector()' Remote CrashApple Safari 4.0.4 / Google Chrome 4.0.249 - CSS style Stack Overflow Denial of Service (PoC)
CVE-2010-0315 2 exploits
CVE-2009-3272 1 exploit
CVE-2008-3950 2 exploits
Apple iPhone Safari WebKit alert()函数远程拒绝服务漏洞Apple iOS 1.1.4/2.0 / iPod 1.1.4/2.0 touch Safari WebKit - 'alert()' Remote Denial of Service
CVE-2011-2334
CVE-2015-6785
CVE-2015-6782
CVE-2015-1155 2 exploits
Mac OS X Safari file:// Redirection Sandbox EscapeMac OS X Safari file:// Redirection Sandbox Escape
CVE-2015-6790
CVE-2015-5788
CVE-2012-5851 2 exploits
WebKit跨站脚本保护绕过漏洞WebKit Cross-Site Scripting Filter - 'Cross-Site ScriptingAuditor.cpp' Security Bypass
CVE-2011-3243
CVE-2011-1059
CVE-2010-2441
CVE-2010-1236
CVE-2009-2419 1 exploit
CVE-2009-1715 1 exploit
CVE-2009-1700 1 exploit
CVE-2010-0650
CVE-2015-1127