CVE-2019-8720
Summary
| CVE | CVE-2019-8720 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-06 23:15:00 UTC |
| Updated | 2023-03-11 02:53:00 UTC |
| Description | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues. |
Risk And Classification
EPSS: 0.040990000 probability, percentile 0.885390000 (date 2026-04-01)
CISA KEV: Listed on 2022-05-23; due 2022-06-13; ransomware use Unknown
Problem Types: CWE-119
CISA Known Exploited Vulnerability
| Vendor | WebKitGTK |
|---|---|
| Product | WebKitGTK |
| Name | WebKitGTK Memory Corruption Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2019-8720 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WebKitGTK and WPE WebKit Security Advisory WSA-2019-0005 - The WebKitGTK Project | MISC | webkitgtk.org | |
| 1876611 – (CVE-2019-8720) CVE-2019-8720 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296075 Oracle Solaris 11.4 Support Repository Update (SRU) 21.69.0 Missing (CPUAPR2020)
- 377553 Alibaba Cloud Linux Security Update for webkitgtk4 (ALINUX2-SA-2020:0147)
- 501286 Alpine Linux Security Update for webkit2gtk
- 501936 Alpine Linux Security Update for webkit2gtk
- 505507 Alpine Linux Security Update for webkit2gtk
- 770068 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2021:0436)
- 940362 AlmaLinux Security Update for GNOME (ALSA-2020:4451)
- 960761 Rocky Linux Security Update for GNOME (RLSA-2020:4451)