RHSA-2020:4035MediumCVSS 8.8

Red Hat Security Advisory: webkitgtk4 security, bug fix, and enhancement update

Published
September 29, 2020
Last Modified
June 26, 2026

🔗 CVE IDs covered (104)

CVE-2019-8680CVE-2019-8768CVE-2019-11070CVE-2019-8544CVE-2019-8623CVE-2019-8649CVE-2019-8671CVE-2019-8771CVE-2019-8816CVE-2019-8844CVE-2020-3868CVE-2019-8536CVE-2019-8559CVE-2019-8571CVE-2019-8601CVE-2019-8607CVE-2019-8676CVE-2019-8815CVE-2019-8819CVE-2019-8506CVE-2019-8611CVE-2019-8820CVE-2020-3895CVE-2020-3900CVE-2019-8688CVE-2019-8584CVE-2019-8535CVE-2019-8615CVE-2019-8735CVE-2019-8821CVE-2020-3897CVE-2020-3901CVE-2019-8563CVE-2019-8608CVE-2019-8733CVE-2019-8769CVE-2019-8782CVE-2019-8808CVE-2019-8822CVE-2020-3864CVE-2019-8558CVE-2019-8594CVE-2019-8674CVE-2019-8689CVE-2020-3867CVE-2020-3885CVE-2020-10018CVE-2019-8719CVE-2019-8524CVE-2019-8678CVE-2019-8835CVE-2020-11793CVE-2021-30666CVE-2019-8677CVE-2019-8684CVE-2019-8783CVE-2020-3865CVE-2019-8610CVE-2019-8622CVE-2019-8681CVE-2019-8683CVE-2019-8690CVE-2019-8763CVE-2019-8811CVE-2020-3899CVE-2019-8587CVE-2019-8609CVE-2019-8686CVE-2019-8726CVE-2019-8743CVE-2019-8764CVE-2020-3902CVE-2021-30761CVE-2019-8666CVE-2019-8707CVE-2019-8766CVE-2021-30762CVE-2019-6237CVE-2019-6251CVE-2019-8583CVE-2019-8597CVE-2019-8658CVE-2019-8823CVE-2020-3862CVE-2020-3894CVE-2019-8551CVE-2019-8710CVE-2019-8720CVE-2019-8765CVE-2019-8812CVE-2019-8846CVE-2019-8595CVE-2019-8596CVE-2019-8619CVE-2019-8669CVE-2019-8672CVE-2019-8687CVE-2019-8813CVE-2019-8814CVE-2019-8586CVE-2019-8625CVE-2019-8644CVE-2019-8673CVE-2019-8679

📋 Description

CVE-2019-6237 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-6251 — webkitgtk: processing maliciously crafted web content lead to URI spoofing CVE-2019-8506 — webkitgtk: malicous web content leads to arbitrary code execution CVE-2019-8524 — webkitgtk: malicious web content leads to arbitrary code execution CVE-2019-8535 — webkitgtk: malicious crafted web content leads to arbitrary code execution CVE-2019-8536 — webkitgtk: malicious crafted web content leads to arbitrary code execution CVE-2019-8544 — webkitgtk: malicious crafted web content leads to arbitrary we content CVE-2019-8551 — webkitgtk: malicious web content leads to cross site scripting CVE-2019-8558 — webkitgtk: malicious crafted web content leads to arbitrary code execution CVE-2019-8559 — webkitgtk: malicious web content leads to arbitrary code execution CVE-2019-8563 — webkitgtk: malicious web content leads to arbitrary code execution CVE-2019-8571 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8583 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8584 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8586 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8587 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8594 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8595 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8596 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8597 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8601 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8607 — webkitgtk: Out-of-bounds read leading to memory disclosure CVE-2019-8608 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8609 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8610 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8611 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8615 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8619 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8622 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8623 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8625 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2019-8644 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8649 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2019-8658 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2019-8666 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8669 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8671 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8672 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8673 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8674 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2019-8676 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8677 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8678 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8679 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8680 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8681 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8683 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8684 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8686 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8687 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8688 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8689 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8690 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2019-8707 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8710 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8719 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2019-8720 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8726 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8733 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8735 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8743 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8763 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8764 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2019-8765 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8766 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8768 — webkitgtk: Browsing history could not be deleted CVE-2019-8769 — webkitgtk: Websites could reveal browsing history CVE-2019-8771 — webkitgtk: Violation of iframe sandboxing policy CVE-2019-8782 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8783 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8808 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8811 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8812 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8813 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2019-8814 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8815 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8816 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8819 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8820 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8821 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8822 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8823 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8835 — webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution CVE-2019-8844 — webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution CVE-2019-8846 — webkitgtk: Use after free issue may lead to remote code execution CVE-2019-11070 — webkitgtk: HTTP proxy setting deanonymization information disclosure CVE-2020-3862 — webkitgtk: Denial of service via incorrect memory handling CVE-2020-3864 — webkitgtk: Non-unique security origin for DOM object contexts CVE-2020-3865 — webkitgtk: Incorrect security check for a top-level DOM object context CVE-2020-3867 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2020-3868 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2020-3885 — webkitgtk: Incorrect processing of file URLs CVE-2020-3894 — webkitgtk: Race condition allows reading of restricted memory CVE-2020-3895 — webkitgtk: Memory corruption triggered by a malicious web content CVE-2020-3897 — webkitgtk: Type confusion leading to arbitrary code execution CVE-2020-3899 — webkitgtk: Memory consumption issue leading to arbitrary code execution CVE-2020-3900 — webkitgtk: Memory corruption triggered by a malicious web content CVE-2020-3901 — webkitgtk: Type confusion leading to arbitrary code execution CVE-2020-3902 — webkitgtk: Input validation issue leading to cross-site script attack CVE-2020-10018 — webkitgtk: Use-after-free issue in accessibility/AXObjectCache.cpp CVE-2020-11793 — webkitgtk: use-after-free via crafted web content CVE-2021-30666 — webkitgtk: Buffer overflow leading to arbitrary code execution CVE-2021-30761 — webkitgtk: Memory corruption leading to arbitrary code execution CVE-2021-30762 — webkitgtk: Use-after-free leading to arbitrary code execution

🔗 References (106)