Epiphany

Vendor:

First CVE: May 2, 2005 · Active for 21 years

13
Total CVEs
More Total CVEs than 91% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Epiphany over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Feb 20, 2023
1,250 days ago

CVE Severity & Scoring

Epiphany13 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (76.9%)
Unknown3 (23.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (76.9%)
High0 (0.0%)
Unknown3 (23.1%)
User Interaction
None5 (38.5%)
Unknown3 (23.1%)
Required5 (38.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (76.9%)
Unknown3 (23.1%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issu
Apr 20, 20227.527NONO
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
Feb 20, 20237.525NONO
ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that trig
May 23, 20187.524NONO
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.
Dec 16, 20216.123NONO
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often e
Dec 16, 20216.123NONO
libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write call
Jun 7, 20187.523NONO
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
Dec 16, 20216.122NONO
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.
Dec 16, 20216.122NONO
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be di
Jan 14, 20198.122NONO
GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting
Jul 17, 20177.521NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Epiphany

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.23.417.51.4%00
3.23.317.51.4%00
3.23.2.117.51.4%00
3.23.217.51.4%00
3.23.1.217.51.4%00
3.23.1.117.51.4%00
3.23.117.51.4%00
3.22.517.51.4%00
3.22.417.51.4%00
3.22.317.51.4%00
3.22.217.51.4%00
3.22.117.51.4%00
3.22.017.51.4%00
3.20.617.51.4%00
3.20.517.51.4%00
3.20.417.51.4%00
3.20.317.51.4%00
3.20.217.51.4%00
3.20.117.51.4%00
3.20.017.51.4%00