🪟 Windows TippsGrok for PC: Using xAI’s Chat Assistant On a Bigger Screen(16.09.2026 um 09:33 Uhr)
🪟 Windows TippsWindows 11 26H2: Release, Neuerungen und wer jetzt handeln muss(16.09.2026 um 09:37 Uhr)
🪟 Windows TippsGoogle Chrome(16.09.2026 um 08:30 Uhr)
🪟 Windows TippsGoogle stopft mehrere kritische Chrome-Lücken(16.09.2026 um 09:24 Uhr)
🪟 Windows TippsKI-Power für eine klare Sprache(16.09.2026 um 08:45 Uhr)
🤖 Android TippsDas Ende einer Ära: Samsung-Nutzer müssen sich umstellen(16.09.2026 um 08:25 Uhr)
🪟 Windows TippsGrok for PC: Using xAI’s Chat Assistant On a Bigger Screen(16.09.2026 um 09:33 Uhr)
🪟 Windows TippsWindows 11 26H2: Release, Neuerungen und wer jetzt handeln muss(16.09.2026 um 09:37 Uhr)
🪟 Windows TippsGoogle Chrome(16.09.2026 um 08:30 Uhr)
🪟 Windows TippsGoogle stopft mehrere kritische Chrome-Lücken(16.09.2026 um 09:24 Uhr)
🪟 Windows TippsKI-Power für eine klare Sprache(16.09.2026 um 08:45 Uhr)
🤖 Android TippsDas Ende einer Ära: Samsung-Nutzer müssen sich umstellen(16.09.2026 um 08:25 Uhr)

🐧 Unix Server 🕛 vor 1 Monat 5 Min Lesezeit CVE-2024-4367
0

DSA-6398-1 webkit2gtk - security update

Cyber Threat & Vulnerability Dossier CVSS 7.5 HIGH (Heuristik) EPSS 24.9%
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
⛔ Dienstausfall (DoS) / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-119: Memory Corruption
Handlungsempfehlung: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
Im CVE-Radar öffnen
↗ Quelle (lists.debian.org)
🔬 IoC Intelligence (39 Indikatoren erkannt)
CVE-2024-4367CVE-2026-28847CVE-2026-28883CVE-2026-28901CVE-2026-28902CVE-2026-28903CVE-2026-28904CVE-2026-28905+31 weitere
🗣️ Stimme:
The following vulnerabilities have been discovered in the WebKitGTK
web engine:


CVE-2024-4367


Thomas Rinsma discovered that a type check was missing when
handling fonts in PDF.js, which would allow arbitrary JavaScript
execution in the PDF.js context.


CVE-2026-28847


DARKNAVY, an anonymous researcher and Daniel Rhea discovered that
processing maliciously crafted web content may lead to an
unexpected process crash.


CVE-2026-28883


Kwak Kiyong discovered that processing maliciously crafted web
content may lead to an unexpected process crash.


CVE-2026-28901


Joshua Rogers, Luigino Camastra, Igor Morgenstern, Guido Vranken,
Maher Azzouzi and Ngan Nguyen discovered that processing
maliciously crafted web content may lead to an unexpected process
crash.


CVE-2026-28902


Tristan Madani and Nathaniel Oh discovered that processing
maliciously crafted web content may lead to an unexpected process
crash.


CVE-2026-28903


Mateusz Krzywicki discovered that processing maliciously crafted
web content may lead to an unexpected process crash.


CVE-2026-28904


Luka Racki discovered that processing maliciously crafted web
content may lead to an unexpected process crash.


CVE-2026-28905


Yuhao Hu, Yuanming Lai, Chenggang Wu, and Zhe Wang discovered that
processing maliciously crafted web content may lead to an
unexpected process crash.


CVE-2026-28907


Cantina discovered that processing maliciously crafted web content
may prevent Content Security Policy from being enforced.


CVE-2026-28942


Milad Nasr and Nicholas Carlini discovered that processing
maliciously crafted web content may lead to an unexpected Safari
crash.


CVE-2026-28946


Gia Bui, dr3dd, and w0wbox discovered that processing maliciously
crafted web content may lead to an unexpected Safari crash.


CVE-2026-28947


dr3dd discovered that processing maliciously crafted web content
may lead to an unexpected Safari crash.


CVE-2026-28953


Maher Azzouzi discovered that processing maliciously crafted web
content may lead to an unexpected process crash.


CVE-2026-28955


wac and Kookhwan Lee discovered that processing maliciously
crafted web content may lead to an unexpected process crash.


CVE-2026-28958


Cantina discovered that an app may be able to access sensitive
user data.


CVE-2026-39872


Utkarsh Pal and Ignacio Sanmillan discovered that processing
maliciously crafted web content may lead to an unexpected process
crash.


CVE-2026-43658


Do Young Park discovered that processing maliciously crafted web
content may lead to an unexpected Safari crash.


CVE-2026-43660


Cantina discovered that processing maliciously crafted web content
may prevent Content Security Policy from being enforced.


CVE-2026-43663


Soyeon Park, Amy Burnett, Khai Tran, sherkito, Kota Toda,
HexRabbit, NiNi, Tristan Madani and Brian Carpenter discovered
that processing maliciously crafted web content may lead to an
unexpected process crash.


CVE-2026-43676


Mateusz Krzywicki, dr3dd, and Tommy DeVoss discovered that
processing maliciously crafted web content may lead to an
unexpected process crash.


CVE-2026-43699


Tommy DeVoss discovered that processing maliciously crafted web
content may lead to an unexpected process crash.


CVE-2026-43701


Aaron Grattafiori discovered that a malicious website may be able
to process restricted web content outside the sandbox.


CVE-2026-43705


dr3dd discovered that processing maliciously crafted web content
may lead to memory corruption.


CVE-2026-43707


Amy Burnett discovered that processing maliciously crafted web
content may lead to an unexpected process crash.


CVE-2026-43712


Kwak Kiyong, Song Nuri, and Tristan Madani discovered that
processing maliciously crafted web content may lead to an
unexpected process crash.


CVE-2026-43713


Jody Ritonga discovered that visiting a website may leak sensitive
data.


CVE-2026-43715


Milad Nasr and Nicholas Carlini discovered that processing
maliciously crafted web content may lead to memory corruption.


CVE-2026-43716


Tuan, Duc, Amy Burnett and Evan Lambert discovered that processing
maliciously crafted web content may lead to an unexpected process
crash.


CVE-2026-43720


Gia Bui and Josef Korbel discovered that processing maliciously
crafted web content may lead to an unexpected process crash.


CVE-2026-43721


Idan Masas discovered that a malicious website may be able to
silently hijack clipboard data.


CVE-2026-43725


Luke Francis discovered that a malicious website may be able to
process restricted web content outside the sandbox.


CVE-2026-43726


Josef Korbel, Tristan Madani, Gia Bui and Narendra Singh
discovered that processing maliciously crafted web content may
lead to an unexpected process crash.


CVE-2026-43727


Tommy DeVoss, Gia Bui and Gurpreet Shergill discovered that
processing maliciously crafted web content may lead to an
unexpected process crash.


CVE-2026-43731


dr3dd discovered that processing maliciously crafted web content
may lead to memory corruption.


CVE-2026-43732


Nan Wang discovered that processing maliciously crafted web
content may disclose sensitive user information.


CVE-2026-43734


Jonathan Alush-Aben discovered that processing maliciously crafted
web content may lead to an unexpected process crash.


CVE-2026-43740


Nathaniel Oh and Arni Hardarson discovered that processing
maliciously crafted web content may result in the disclosure of
process memory.


CVE-2026-43742


Yulia Mertsalova discovered that processing maliciously crafted
web content may lead to an unexpected process crash.


CVE-2026-43745


Amy Burnett and Khai Tran discovered that processing maliciously
crafted web content may lead to an unexpected process crash.


https://security-tracker.debian.org/tracker/DSA-6398-1

Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf lists.debian.org.
↗ Original-Artikel auf lists.debian.org lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Eine Tonne „grüner“ Stahl am Tag: US-Startup entwickelt neuen Ofen – und will diese alte Industrie umkrempeln
1 Quelle
Diversität im Backlash: Was Unternehmen jetzt tun sollten
1 Quelle
Größer als die Autobranche: Deutschlands Digitalunternehmen erwirtschaften 481 Milliarden Euro
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten DSA-6398-1 webkit2gtk - security update

Thematisch verwandte Begriffe: DSA63981, webkit2gtk, security, update · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...