CVE-2018-4133 PUBLISHED

An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "WebKit" component. A Safari cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

EPSS 0.50% · 65.8th percentile

Risk Scores

EPSS Score
0.50%
65.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSwebkit2gtk0, 2.8.5+dfsg1-3, 2.10.3+dfsg1-1
Ubuntu:16.04:LTSqtwebkit-source2.3.2-0ubuntu10, 2.3.2-0ubuntu11, 0
Ubuntu:16.04:LTSqtwebkit-opensource-src5.4.2+dfsg-1ubuntu2.1, 5.5.1+dfsg-2ubuntu1, 0
Ubuntu:20.04:LTSqtwebkit-opensource-src5.212.0~alpha3-6, 5.212.0~alpha3-5, 5.212.0~alpha3-3
Ubuntu:18.04:LTSwebkitgtk0, 2.4.11-3, 2.4.11-3ubuntu2
Ubuntu:24.04:LTSqtwebkit-opensource-src0, 5.212.0~alpha4-34ubuntu3, 5.212.0~alpha4-34ubuntu4
Ubuntu:18.04:LTSqtwebkit-opensource-src5.9.1+dfsg-5ubuntu3, 5.9.1+dfsg-5ubuntu1, 5.212.0~alpha2-7
Ubuntu:18.04:LTSqtwebkit-source2.3.2-0ubuntu13, 0
Ubuntu:16.04:LTSwebkitgtk2.4.9-2ubuntu2, 2.4.10-0ubuntu1, 2.4.11-0ubuntu0.1
Ubuntu:22.04:LTSqtwebkit-opensource-src5.212.0~alpha4-12, 0, 5.212.0~alpha4-14

Timeline

References

Open in Interactive Console →