Known vulnerabilities in webkit2gtk (Debian package) 2.34.3-1~deb11u1

Vendor: Debian
Version: 2.34.3-1~deb11u1
Software CPE: cpe:2.3:o:debian:webkit2gtk_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 14
Public exploits: 2
Known exploited (KEV): 2
Highest CVSSv4 Score: 8.7

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting webkit2gtk (Debian package) version 2.34.3-1~deb11u1 webkit2gtk (Debian package) 2.34.3-1~deb11u1 is affected by 14 vulnerabilities: 1 critical, 11 high, 2 medium Critical High Medium Low

Vulnerabilities (14)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU61337 - Heap-based Buffer Overflow
CVE-2022-22629
CWE-122 High
Public exploit available
No
2.36.0-3~deb10u1, 2.36.0-3~deb11u1 14.03.2022 SB2022031433
SB2022031436
SB2022031437
and 33 more
#VU61336 - Use After Free
CVE-2022-22628
CWE-416 High
No
No
2.36.0-3~deb10u1, 2.36.0-3~deb11u1 14.03.2022 SB2022031433
SB2022031436
SB2022031437
and 32 more
#VU61335 - Use After Free
CVE-2022-22624
CWE-416 High
No
No
2.36.0-3~deb10u1, 2.36.0-3~deb11u1 14.03.2022 SB2022031433
SB2022031436
SB2022031437
and 32 more
#VU60520 - Use After Free
CVE-2022-22620
CWE-416 Critical
Public exploit available
Exploited
2.34.6-1~deb10u1, 2.34.6-1~deb11u1 10.02.2022 SB2022021012
SB2022021013
SB2022021014
and 11 more
#VU60038 - Security Features
CVE-2022-22592
CWE-254 Medium
No
No
2.34.6-1~deb10u1, 2.34.6-1~deb11u1 26.01.2022 SB2022012633
SB2022012635
SB2022012636
and 16 more
#VU60037 - Use After Free
CVE-2022-22590
CWE-416 High
No
No
2.34.6-1~deb10u1, 2.34.6-1~deb11u1 26.01.2022 SB2022012633
SB2022012635
SB2022012636
and 16 more
#VU60036 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22589
CWE-94 Medium
No
No
2.34.6-1~deb10u1, 2.34.6-1~deb11u1 26.01.2022 SB2022012633
SB2022012635
SB2022012636
and 19 more
#VU58891 - Type confusion
CVE-2021-30954
CWE-843 High
No
No
2.34.4-1~deb10u1, 2.34.4-1~deb11u1 14.12.2021 SB2021121429
SB2021121432
SB2021121433
and 15 more
#VU58890 - Out-of-bounds read
CVE-2021-30953
CWE-125 High
No
No
2.34.4-1~deb10u1, 2.34.4-1~deb11u1 14.12.2021 SB2021121429
SB2021121432
SB2021121433
and 15 more
#VU58889 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2021-30984
CWE-362 High
No
No
2.34.4-1~deb10u1, 2.34.4-1~deb11u1 14.12.2021 SB2021121429
SB2021121432
SB2021121433
and 15 more
#VU58888 - Integer overflow
CVE-2021-30952
CWE-190 High
No
Exploited
2.34.4-1~deb10u1, 2.34.4-1~deb11u1 14.12.2021 SB2021121429
SB2021121432
SB2021121433
and 15 more
#VU58887 - Use After Free
CVE-2021-30951
CWE-416 High
No
No
2.34.4-1~deb10u1, 2.34.4-1~deb11u1 14.12.2021 SB2021121429
SB2021121432
SB2021121433
and 15 more
#VU58886 - Use After Free
CVE-2021-30936
CWE-416 High
No
No
2.34.4-1~deb10u1, 2.34.4-1~deb11u1 14.12.2021 SB2021121429
SB2021121432
SB2021121433
and 15 more
#VU58885 - Memory corruption
CVE-2021-30934
CWE-119 High
No
No
2.34.4-1~deb10u1, 2.34.4-1~deb11u1 14.12.2021 SB2021121429
SB2021121432
SB2021121433
and 15 more