webkitgtk-6.0

Link package | bugs open | bugs closed | Wiki | GitHub | web search
Description Web content engine for GTK
Version 2.48.3-1 [extra]

Open

Group Affected Fixed Severity Status Ticket
AVG-2866 2.48.2-1 2.49.1-1 High Vulnerable
Issue Group Severity Remote Type Description
CVE-2025-31257 AVG-2866 High Yes Denial of service
Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in an unexpected crash.
CVE-2025-31215 AVG-2866 Medium Yes Denial of service
Processing malicious web content can cause a NULL pointer dereference due to improper checks, resulting in an unexpected process crash.
CVE-2025-31206 AVG-2866 High Yes Denial of service
Processing malicious web content can cause a type confusion issue due to improper state handling and result in an unexpected crash.
CVE-2025-31205 AVG-2866 High Yes Information disclosure
A malicious website may steal data cross-origin due to improper security checks within the web browser or rendering engine, leading to unauthorized...
CVE-2025-31204 AVG-2866 High Yes Insufficient validation
Processing malicious web content can cause out-of-bounds memory access due to improper memory handling and result in memory corruption.
CVE-2025-24223 AVG-2866 High Yes Incorrect calculation
Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.

Resolved

Group Affected Fixed Severity Status Ticket
AVG-2867 2.42.0-1 2.48.2-1 High Fixed
Issue Group Severity Remote Type Description
CVE-2023-42970 AVG-2867 High Yes Arbitrary code execution
Processing malicious web content can cause a use-after-free issue due to improper memory management and result in arbitrary code execution.
CVE-2023-42875 AVG-2867 High Yes Arbitrary code execution
Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in arbitrary code execution. The issue was...

Advisories

Date Advisory Group Severity Type
18 May 2025 ASA-202505-5 AVG-2867 High arbitrary code execution