Vulnerability Intelligence Report
WebKitGTK Memory Corruption Vulnerability
CVE-2019-8720
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:1.56%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-119 ↗CWE-119
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| webkitgtk | webkitgtk | all |
| wpewebkit | wpe_webkit | all |
| redhat | codeready_linux_builder | 8.0 |
| redhat | codeready_linux_builder_eus | 8.4, 8.6 |
| redhat | codeready_linux_builder_for_arm64_eus | 8.0, 8.4, 8.6 |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus | 8.0, 8.4, 8.6 |
| redhat | codeready_linux_builder_for_power_little_endian_eus | 8.0, 8.4, 8.6 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_eus | 8.4, 8.6 |
| redhat | enterprise_linux_for_arm64_eus | 8.6 |
| redhat | enterprise_linux_for_ibm_z_systems | 7.0, 8.0 |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 8.4, 8.6 |
| redhat | enterprise_linux_for_power_big_endian | 7.0 |
| redhat | enterprise_linux_for_power_little_endian | 7.0, 8.0 |
| redhat | enterprise_linux_for_power_little_endian_eus | 8.4, 8.6 |
| redhat | enterprise_linux_for_scientific_computing | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 8.4, 8.6 |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.4, 8.6 |
| redhat | enterprise_linux_server_tus | 8.4, 8.6 |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | 8.4, 8.6 |
| redhat | enterprise_linux_workstation | 7.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2019-02-18T00:00:00 |
| Published | 2023-03-06T00:00:00 |
| Last Updated | 2025-10-21T23:15:24 |
Community Chatter & Buzz