<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for webkit2gtk3</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2017:2991-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2017-11-10T13:25:29Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2017-11-10T13:25:29Z</InitialReleaseDate>
    <CurrentReleaseDate>2017-11-10T13:25:29Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for webkit2gtk3</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for webkit2gtk3 to version 2.18.0 fixes the following issues:

These security issues were fixed:

- CVE-2017-7039: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and application
  crash) via a crafted web site (bsc#1050469).
- CVE-2017-7018: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and application
  crash) via a crafted web site (bsc#1050469).
- CVE-2017-7030: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and application
  crash) via a crafted web site (bsc#1050469).
- CVE-2017-7037: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and application
  crash) via a crafted web site (bsc#1050469).
- CVE-2017-7034: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and application
  crash) via a crafted web site (bsc#1050469).
- CVE-2017-7055: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and application
  crash) via a crafted web site (bsc#1050469).
- CVE-2017-7056: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and application
  crash) via a crafted web site (bsc#1050469).
- CVE-2017-7064: An issue was fixed that allowed remote attackers to bypass
  intended memory-read restrictions via a crafted app (bsc#1050469).
- CVE-2017-7061: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and application
  crash) via a crafted web site (bsc#1050469).
- CVE-2017-7048: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and application
  crash) via a crafted web site (bsc#1050469).
- CVE-2017-7046: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1050469).
- CVE-2017-2538: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and application
  crash) via a crafted web site (bsc#1045460)
- CVE-2017-2496: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and application
  crash) via a crafted web site.
- CVE-2017-2539: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and application
  crash) via a crafted web site.
- CVE-2017-2510: An issue was fixed that allowed remote attackers to conduct
  Universal XSS (UXSS) attacks via a crafted web site that improperly
  interacts with pageshow events.
- CVE-2017-2365: An issue was fixed that allowed remote attackers to bypass the
  Same Origin Policy and obtain sensitive information via a crafted web
  site (bsc#1024749)
- CVE-2017-2366: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1024749)
- CVE-2017-2373: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1024749)
- CVE-2017-2363: An issue was fixed that allowed remote attackers to bypass the
  Same Origin Policy and obtain sensitive information via a crafted web
  site (bsc#1024749)
- CVE-2017-2362: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1024749)
- CVE-2017-2350: An issue was fixed that allowed remote attackers to bypass the
  Same Origin Policy and obtain sensitive information via a crafted web
  site (bsc#1024749)
- CVE-2017-2350: An issue was fixed that allowed remote attackers to bypass the
  Same Origin Policy and obtain sensitive information via a crafted web site
  (bsc#1024749)
- CVE-2017-2354: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1024749).
- CVE-2017-2355: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (uninitialized memory
  access and application crash) via a crafted web site (bsc#1024749)
- CVE-2017-2356: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1024749)
- CVE-2017-2371: An issue was fixed that allowed remote attackers to launch
  popups via a crafted web site (bsc#1024749)
- CVE-2017-2364: An issue was fixed that allowed remote attackers to bypass the
  Same Origin Policy and obtain sensitive information via a crafted web
  site (bsc#1024749)
- CVE-2017-2369: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1024749)
- CVE-2016-7656: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1020950)
- CVE-2016-7635: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1020950)
- CVE-2016-7654: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1020950)
- CVE-2016-7639: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1020950)
- CVE-2016-7645: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1020950)
- CVE-2016-7652: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1020950)
- CVE-2016-7641: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1020950)
- CVE-2016-7632: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1020950)
- CVE-2016-7599: An issue was fixed that allowed remote attackers to bypass the
  Same Origin Policy and obtain sensitive information via a crafted web
  site that used HTTP redirects (bsc#1020950)
- CVE-2016-7592: An issue was fixed that allowed remote attackers to obtain
  sensitive information via crafted JavaScript prompts on a web site (bsc#1020950)
- CVE-2016-7589: An issue was fixed that allowed remote attackers to execute
  arbitrary code or cause a denial of service (memory corruption and
  application crash) via a crafted web site (bsc#1020950)
- CVE-2016-7623: An issue was fixed that allowed remote attackers to obtain
  sensitive information via a blob URL on a web site (bsc#1020950)
- CVE-2016-7586: An issue was fixed that allowed remote attackers to obtain
  sensitive information via a crafted web site (bsc#1020950)

For other non-security fixes please check the changelog.

This update was imported from the SUSE:SLE-12-SP2:Update update project.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      <Description>E-Mail link for openSUSE-SU-2017:2991-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 42.2">
      <Branch Type="Product Name" Name="openSUSE Leap 42.2">
        <FullProductName ProductID="openSUSE Leap 42.2">openSUSE Leap 42.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 42.3">
      <Branch Type="Product Name" Name="openSUSE Leap 42.3">
        <FullProductName ProductID="openSUSE Leap 42.3">openSUSE Leap 42.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libjavascriptcoregtk-4_0-18-2.18.0-5.1">
      <FullProductName ProductID="libjavascriptcoregtk-4_0-18-2.18.0-5.1">libjavascriptcoregtk-4_0-18-2.18.0-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1">
      <FullProductName ProductID="libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1">libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebkit2gtk-4_0-37-2.18.0-5.1">
      <FullProductName ProductID="libwebkit2gtk-4_0-37-2.18.0-5.1">libwebkit2gtk-4_0-37-2.18.0-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebkit2gtk-4_0-37-32bit-2.18.0-5.1">
      <FullProductName ProductID="libwebkit2gtk-4_0-37-32bit-2.18.0-5.1">libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebkit2gtk3-lang-2.18.0-5.1">
      <FullProductName ProductID="libwebkit2gtk3-lang-2.18.0-5.1">libwebkit2gtk3-lang-2.18.0-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1">
      <FullProductName ProductID="typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1">typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-WebKit2-4_0-2.18.0-5.1">
      <FullProductName ProductID="typelib-1_0-WebKit2-4_0-2.18.0-5.1">typelib-1_0-WebKit2-4_0-2.18.0-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1">
      <FullProductName ProductID="typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1">typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="webkit-jsc-4-2.18.0-5.1">
      <FullProductName ProductID="webkit-jsc-4-2.18.0-5.1">webkit-jsc-4-2.18.0-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="webkit2gtk-4_0-injected-bundles-2.18.0-5.1">
      <FullProductName ProductID="webkit2gtk-4_0-injected-bundles-2.18.0-5.1">webkit2gtk-4_0-injected-bundles-2.18.0-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="webkit2gtk3-2.18.0-5.1">
      <FullProductName ProductID="webkit2gtk3-2.18.0-5.1">webkit2gtk3-2.18.0-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="webkit2gtk3-devel-2.18.0-5.1">
      <FullProductName ProductID="webkit2gtk3-devel-2.18.0-5.1">webkit2gtk3-devel-2.18.0-5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="webkit2gtk3-plugin-process-gtk2-2.18.0-5.1">
      <FullProductName ProductID="webkit2gtk3-plugin-process-gtk2-2.18.0-5.1">webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libjavascriptcoregtk-4_0-18-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1">libjavascriptcoregtk-4_0-18-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1">libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebkit2gtk-4_0-37-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1">libwebkit2gtk-4_0-37-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebkit2gtk-4_0-37-32bit-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1">libwebkit2gtk-4_0-37-32bit-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebkit2gtk3-lang-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1">libwebkit2gtk3-lang-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1">typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-WebKit2-4_0-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1">typelib-1_0-WebKit2-4_0-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1">typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit-jsc-4-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1">webkit-jsc-4-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk-4_0-injected-bundles-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1">webkit2gtk-4_0-injected-bundles-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk3-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1">webkit2gtk3-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk3-devel-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1">webkit2gtk3-devel-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk3-plugin-process-gtk2-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.2">
      <FullProductName ProductID="openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1">webkit2gtk3-plugin-process-gtk2-2.18.0-5.1 as a component of openSUSE Leap 42.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="libjavascriptcoregtk-4_0-18-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1">libjavascriptcoregtk-4_0-18-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1">libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebkit2gtk-4_0-37-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1">libwebkit2gtk-4_0-37-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebkit2gtk-4_0-37-32bit-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1">libwebkit2gtk-4_0-37-32bit-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebkit2gtk3-lang-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1">libwebkit2gtk3-lang-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1">typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-WebKit2-4_0-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1">typelib-1_0-WebKit2-4_0-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1">typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit-jsc-4-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1">webkit-jsc-4-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk-4_0-injected-bundles-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1">webkit2gtk-4_0-injected-bundles-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk3-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1">webkit2gtk3-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk3-devel-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1">webkit2gtk3-devel-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk3-plugin-process-gtk2-2.18.0-5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1">webkit2gtk3-plugin-process-gtk2-2.18.0-5.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2016-7586</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7586.html</URL>
        <Description>CVE-2016-7586</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2016-7589</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7589.html</URL>
        <Description>CVE-2016-7589</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component, which allows remote attackers to obtain sensitive information via crafted JavaScript prompts on a web site.</Note>
    </Notes>
    <CVE>CVE-2016-7592</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7592.html</URL>
        <Description>CVE-2016-7592</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that uses HTTP redirects.</Note>
    </Notes>
    <CVE>CVE-2016-7599</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7599.html</URL>
        <Description>CVE-2016-7599</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a blob URL on a web site.</Note>
    </Notes>
    <CVE>CVE-2016-7623</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7623.html</URL>
        <Description>CVE-2016-7623</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2016-7632</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7632.html</URL>
        <Description>CVE-2016-7632</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2016-7635</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7635.html</URL>
        <Description>CVE-2016-7635</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2016-7639</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7639.html</URL>
        <Description>CVE-2016-7639</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2016-7641</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7641.html</URL>
        <Description>CVE-2016-7641</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2016-7645</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7645.html</URL>
        <Description>CVE-2016-7645</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2016-7652</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7652.html</URL>
        <Description>CVE-2016-7652</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2016-7654</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7654.html</URL>
        <Description>CVE-2016-7654</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2016-7656</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-7656.html</URL>
        <Description>CVE-2016-7656</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1020950</URL>
        <Description>SUSE Bug 1020950</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2350</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2350.html</URL>
        <Description>CVE-2017-2350</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024749</URL>
        <Description>SUSE Bug 1024749</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2354</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2354.html</URL>
        <Description>CVE-2017-2354</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024749</URL>
        <Description>SUSE Bug 1024749</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2355</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2355.html</URL>
        <Description>CVE-2017-2355</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024749</URL>
        <Description>SUSE Bug 1024749</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2356</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2356.html</URL>
        <Description>CVE-2017-2356</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024749</URL>
        <Description>SUSE Bug 1024749</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2362</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2362.html</URL>
        <Description>CVE-2017-2362</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024749</URL>
        <Description>SUSE Bug 1024749</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2363</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2363.html</URL>
        <Description>CVE-2017-2363</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024749</URL>
        <Description>SUSE Bug 1024749</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2364</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2364.html</URL>
        <Description>CVE-2017-2364</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024749</URL>
        <Description>SUSE Bug 1024749</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2365</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2365.html</URL>
        <Description>CVE-2017-2365</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024749</URL>
        <Description>SUSE Bug 1024749</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2366</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2366.html</URL>
        <Description>CVE-2017-2366</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024749</URL>
        <Description>SUSE Bug 1024749</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2369</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2369.html</URL>
        <Description>CVE-2017-2369</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024749</URL>
        <Description>SUSE Bug 1024749</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="24">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote attackers to launch popups via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2371</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2371.html</URL>
        <Description>CVE-2017-2371</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024749</URL>
        <Description>SUSE Bug 1024749</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="25">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2373</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2373.html</URL>
        <Description>CVE-2017-2373</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1024749</URL>
        <Description>SUSE Bug 1024749</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="26">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2496</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2496.html</URL>
        <Description>CVE-2017-2496</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="27">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with pageshow events.</Note>
    </Notes>
    <CVE>CVE-2017-2510</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2510.html</URL>
        <Description>CVE-2017-2510</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="28">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2538</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2538.html</URL>
        <Description>CVE-2017-2538</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1045460</URL>
        <Description>SUSE Bug 1045460</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="29">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-2539</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2539.html</URL>
        <Description>CVE-2017-2539</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="30">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-7018</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7018.html</URL>
        <Description>CVE-2017-7018</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="31">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-7030</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7030.html</URL>
        <Description>CVE-2017-7030</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="32">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-7034</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7034.html</URL>
        <Description>CVE-2017-7034</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="33">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-7037</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7037.html</URL>
        <Description>CVE-2017-7037</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="34">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-7039</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7039.html</URL>
        <Description>CVE-2017-7039</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="35">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-7046</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7046.html</URL>
        <Description>CVE-2017-7046</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="36">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-7048</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7048.html</URL>
        <Description>CVE-2017-7048</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="37">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-7055</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7055.html</URL>
        <Description>CVE-2017-7055</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="38">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-7056</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7056.html</URL>
        <Description>CVE-2017-7056</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="39">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.</Note>
    </Notes>
    <CVE>CVE-2017-7061</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7061.html</URL>
        <Description>CVE-2017-7061</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="40">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.</Note>
    </Notes>
    <CVE>CVE-2017-7064</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.2:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.18.0-5.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.18.0-5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2017-11/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-7064.html</URL>
        <Description>CVE-2017-7064</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1050469</URL>
        <Description>SUSE Bug 1050469</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
