ID:6406 - Exploit for Improper input validation in WebKitGTK+ - CVE-2018-11646
Published: June 17, 2021
WebKitGTK+
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to mishandling of an unset pageURL in webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp. A remote attacker can send specially crafted input and cause the service to crash.