peter bassill · operator
$ cve CVE-2020-10018 JSON

CVE-2020-10018

9.8
CRITICAL · CVSS 3.1 · EPSS 5% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.99% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-416
On CISA KEVno
Public exploitnone known
Published2020-03-02
Last modified2026-06-17

Affected (6)

VendorProduct
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
opensuseleap
webkitgtkwebkitgtk
wpewebkitwpe webkit

References

→ the Explorer  ·  watch your stack  ·  NVD