CVE-2019-8375 is a critical buffer overflow vulnerability in the UIProcess subsystem of WebKitGTK and WebKitGTK+, affecting versions through 2.23.90 and 2.22.6 respectively, including products like GNOME Web. This flaw allows remote attackers to trigger a denial of service or potentially achieve other unspecified impacts by manipulating script dialog sizes to exceed web view dimensions. With a CVSS score of 9.8, it is easily exploitable over the network with low complexity and no user interaction, leading to high confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation in the wild or KEV listing, a proof-of-concept denial-of-service exploit is publicly available on ExploitDB, though it lacks broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.23.90CPE matchmatch criteria | cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:* | ||
<= 2.22.6CPE matchmatch criteria | cpe:2.3:a:webkitgtk:webkitgtk\+:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* | ||
42.3CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.