CVE-2019-8720

HIGH KEV

webkitgtk < 2.26.0 - Remote Code Execution via Malicious Web Content

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-8720 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 23, 2022.

Description

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

Scores

CVSS v3 8.8
EPSS 0.0412
EPSS Percentile 88.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-05-23
VulnCheck KEV 2022-05-23
InTheWild.io 2022-05-23
ENISA EUVD EUVD-2019-18110
CWE
CWE-119
Status published
Products (39)
redhat/codeready_linux_builder 8.0
redhat/codeready_linux_builder_eus 8.4
redhat/codeready_linux_builder_eus 8.6
redhat/codeready_linux_builder_for_arm64_eus 8.0
redhat/codeready_linux_builder_for_arm64_eus 8.4
redhat/codeready_linux_builder_for_arm64_eus 8.6
redhat/codeready_linux_builder_for_ibm_z_systems_eus 8.0
redhat/codeready_linux_builder_for_ibm_z_systems_eus 8.4
redhat/codeready_linux_builder_for_ibm_z_systems_eus 8.6
redhat/codeready_linux_builder_for_power_little_endian_eus 8.0
... and 29 more
Published Mar 06, 2023
KEV Added May 23, 2022
Tracked Since Feb 18, 2026