CVE-2025-66287

A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
redhatCNA
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
webkit2gtk
bullseye
vulnerable
trixie
ignored
bookworm
ignored
bullseye (security)
vulnerable
bookworm (security)
vulnerable
trixie (security)
vulnerable
forky
vulnerable
sid
2.50.3-1
fixed
wpewebkit
bullseye (security)
vulnerable
bullseye
vulnerable
trixie
ignored
bookworm
ignored
forky
vulnerable
sid
2.50.3-1
fixed