peter bassill · operator
$ cve CVE-2019-8720 JSON

CVE-2019-8720 KEV

8.8
HIGH · CVSS 3.1 · EPSS 1.6% (pctl 74)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-13.

Description

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS1.56% — more likely to be exploited than 74% of all CVEs
WeaknessCWE-119
On CISA KEVyes — remediate by 2022-06-13
Public exploitnone known
Published2023-03-06
Last modified2026-06-17

CISA KEV

NameWebKitGTK Memory Corruption Vulnerability
Added2022-05-23
Due2022-06-13
Vendor / productWebKitGTK / WebKitGTK
Ransomware usenone reported

Affected (23)

VendorProduct
redhatcodeready linux builder
redhatcodeready linux builder eus
redhatcodeready linux builder for arm64 eus
redhatcodeready linux builder for ibm z systems eus
redhatcodeready linux builder for power little endian eus
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux for arm64 eus
redhatenterprise linux for ibm z systems
redhatenterprise linux for ibm z systems eus
redhatenterprise linux for power big endian
redhatenterprise linux for power little endian
redhatenterprise linux for power little endian eus
redhatenterprise linux for scientific computing
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server for power little endian update services for sap solutions
redhatenterprise linux server tus
redhatenterprise linux server update services for sap solutions
redhatenterprise linux workstation
webkitgtkwebkitgtk
wpewebkitwpe webkit

References

→ the Explorer  ·  watch your stack  ·  NVD