<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for webkit2gtk3</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2019:0068-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2019-01-21T12:03:35Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2019-01-21T12:03:35Z</InitialReleaseDate>
    <CurrentReleaseDate>2019-01-21T12:03:35Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for webkit2gtk3</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for webkit2gtk3 to version 2.22.4 fixes the following issues:

Security issues fixed:

  CVE-2018-4191, CVE-2018-4197, CVE-2018-4299, CVE-2018-4306, CVE-2018-4309, CVE-2018-4392,
  CVE-2018-4312, CVE-2018-4314, CVE-2018-4315, CVE-2018-4316, CVE-2018-4317, CVE-2018-4318,
  CVE-2018-4319, CVE-2018-4323, CVE-2018-4328, CVE-2018-4358, CVE-2018-4359, CVE-2018-4361,
  CVE-2018-4345, CVE-2018-4372, CVE-2018-4373, CVE-2018-4375, CVE-2018-4376, CVE-2018-4416,
  CVE-2018-4378, CVE-2018-4382, CVE-2018-4386 (bsc#1110279, bsc#1116998). 
  
This update was imported from the SUSE:SLE-12-SP2:Update update project.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      <Description>E-Mail link for openSUSE-SU-2019:0068-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 42.3">
      <Branch Type="Product Name" Name="openSUSE Leap 42.3">
        <FullProductName ProductID="openSUSE Leap 42.3">openSUSE Leap 42.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libjavascriptcoregtk-4_0-18-2.22.4-15.1">
      <FullProductName ProductID="libjavascriptcoregtk-4_0-18-2.22.4-15.1">libjavascriptcoregtk-4_0-18-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1">
      <FullProductName ProductID="libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1">libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebkit2gtk-4_0-37-2.22.4-15.1">
      <FullProductName ProductID="libwebkit2gtk-4_0-37-2.22.4-15.1">libwebkit2gtk-4_0-37-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebkit2gtk-4_0-37-32bit-2.22.4-15.1">
      <FullProductName ProductID="libwebkit2gtk-4_0-37-32bit-2.22.4-15.1">libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebkit2gtk3-lang-2.22.4-15.1">
      <FullProductName ProductID="libwebkit2gtk3-lang-2.22.4-15.1">libwebkit2gtk3-lang-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1">
      <FullProductName ProductID="typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1">typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-WebKit2-4_0-2.22.4-15.1">
      <FullProductName ProductID="typelib-1_0-WebKit2-4_0-2.22.4-15.1">typelib-1_0-WebKit2-4_0-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1">
      <FullProductName ProductID="typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1">typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="webkit-jsc-4-2.22.4-15.1">
      <FullProductName ProductID="webkit-jsc-4-2.22.4-15.1">webkit-jsc-4-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="webkit2gtk-4_0-injected-bundles-2.22.4-15.1">
      <FullProductName ProductID="webkit2gtk-4_0-injected-bundles-2.22.4-15.1">webkit2gtk-4_0-injected-bundles-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="webkit2gtk3-2.22.4-15.1">
      <FullProductName ProductID="webkit2gtk3-2.22.4-15.1">webkit2gtk3-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="webkit2gtk3-devel-2.22.4-15.1">
      <FullProductName ProductID="webkit2gtk3-devel-2.22.4-15.1">webkit2gtk3-devel-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="webkit2gtk3-minibrowser-2.22.4-15.1">
      <FullProductName ProductID="webkit2gtk3-minibrowser-2.22.4-15.1">webkit2gtk3-minibrowser-2.22.4-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="webkit2gtk3-plugin-process-gtk2-2.22.4-15.1">
      <FullProductName ProductID="webkit2gtk3-plugin-process-gtk2-2.22.4-15.1">webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libjavascriptcoregtk-4_0-18-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1">libjavascriptcoregtk-4_0-18-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1">libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebkit2gtk-4_0-37-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1">libwebkit2gtk-4_0-37-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebkit2gtk-4_0-37-32bit-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1">libwebkit2gtk-4_0-37-32bit-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebkit2gtk3-lang-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1">libwebkit2gtk3-lang-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1">typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-WebKit2-4_0-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1">typelib-1_0-WebKit2-4_0-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1">typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit-jsc-4-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1">webkit-jsc-4-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk-4_0-injected-bundles-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1">webkit2gtk-4_0-injected-bundles-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk3-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1">webkit2gtk3-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk3-devel-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1">webkit2gtk3-devel-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk3-minibrowser-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1">webkit2gtk3-minibrowser-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="webkit2gtk3-plugin-process-gtk2-2.22.4-15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 42.3">
      <FullProductName ProductID="openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1">webkit2gtk3-plugin-process-gtk2-2.22.4-15.1 as a component of openSUSE Leap 42.3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4191</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4191.html</URL>
        <Description>CVE-2018-4191</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4197</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4197.html</URL>
        <Description>CVE-2018-4197</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.</Note>
    </Notes>
    <CVE>CVE-2018-4207</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4207.html</URL>
        <Description>CVE-2018-4207</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.</Note>
    </Notes>
    <CVE>CVE-2018-4208</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4208.html</URL>
        <Description>CVE-2018-4208</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.</Note>
    </Notes>
    <CVE>CVE-2018-4209</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4209.html</URL>
        <Description>CVE-2018-4209</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.</Note>
    </Notes>
    <CVE>CVE-2018-4210</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4210.html</URL>
        <Description>CVE-2018-4210</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.</Note>
    </Notes>
    <CVE>CVE-2018-4212</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4212.html</URL>
        <Description>CVE-2018-4212</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.</Note>
    </Notes>
    <CVE>CVE-2018-4213</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4213.html</URL>
        <Description>CVE-2018-4213</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.</Note>
    </Notes>
    <CVE>CVE-2018-4261</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4261.html</URL>
        <Description>CVE-2018-4261</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104169</URL>
        <Description>SUSE Bug 1104169</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.</Note>
    </Notes>
    <CVE>CVE-2018-4262</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4262.html</URL>
        <Description>CVE-2018-4262</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104169</URL>
        <Description>SUSE Bug 1104169</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.</Note>
    </Notes>
    <CVE>CVE-2018-4263</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4263.html</URL>
        <Description>CVE-2018-4263</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104169</URL>
        <Description>SUSE Bug 1104169</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.</Note>
    </Notes>
    <CVE>CVE-2018-4264</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4264.html</URL>
        <Description>CVE-2018-4264</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104169</URL>
        <Description>SUSE Bug 1104169</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.</Note>
    </Notes>
    <CVE>CVE-2018-4265</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4265.html</URL>
        <Description>CVE-2018-4265</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104169</URL>
        <Description>SUSE Bug 1104169</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A race condition was addressed with additional validation. This issue affected versions prior toiVersions prior to: OS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.</Note>
    </Notes>
    <CVE>CVE-2018-4266</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4266.html</URL>
        <Description>CVE-2018-4266</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104169</URL>
        <Description>SUSE Bug 1104169</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.</Note>
    </Notes>
    <CVE>CVE-2018-4267</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4267.html</URL>
        <Description>CVE-2018-4267</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104169</URL>
        <Description>SUSE Bug 1104169</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.</Note>
    </Notes>
    <CVE>CVE-2018-4270</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4270.html</URL>
        <Description>CVE-2018-4270</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104169</URL>
        <Description>SUSE Bug 1104169</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.</Note>
    </Notes>
    <CVE>CVE-2018-4272</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4272.html</URL>
        <Description>CVE-2018-4272</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104169</URL>
        <Description>SUSE Bug 1104169</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.</Note>
    </Notes>
    <CVE>CVE-2018-4273</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4273.html</URL>
        <Description>CVE-2018-4273</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104169</URL>
        <Description>SUSE Bug 1104169</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.</Note>
    </Notes>
    <CVE>CVE-2018-4278</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4278.html</URL>
        <Description>CVE-2018-4278</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104169</URL>
        <Description>SUSE Bug 1104169</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A type confusion issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.</Note>
    </Notes>
    <CVE>CVE-2018-4284</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4284.html</URL>
        <Description>CVE-2018-4284</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104169</URL>
        <Description>SUSE Bug 1104169</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4299</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4299.html</URL>
        <Description>CVE-2018-4299</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4306</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4306.html</URL>
        <Description>CVE-2018-4306</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4309</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4309.html</URL>
        <Description>CVE-2018-4309</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="24">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4312</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4312.html</URL>
        <Description>CVE-2018-4312</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="25">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4314</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4314.html</URL>
        <Description>CVE-2018-4314</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="26">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4315</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4315.html</URL>
        <Description>CVE-2018-4315</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="27">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A memory corruption issue was addressed with improved state management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4316</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4316.html</URL>
        <Description>CVE-2018-4316</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="28">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4317</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4317.html</URL>
        <Description>CVE-2018-4317</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="29">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4318</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4318.html</URL>
        <Description>CVE-2018-4318</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="30">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue affected versions prior to iOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4319</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4319.html</URL>
        <Description>CVE-2018-4319</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="31">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4323</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4323.html</URL>
        <Description>CVE-2018-4323</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="32">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4328</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4328.html</URL>
        <Description>CVE-2018-4328</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="33">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4345</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4345.html</URL>
        <Description>CVE-2018-4345</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1116998</URL>
        <Description>SUSE Bug 1116998</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="34">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4358</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4358.html</URL>
        <Description>CVE-2018-4358</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="35">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4359</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4359.html</URL>
        <Description>CVE-2018-4359</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="36">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A memory consumption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.</Note>
    </Notes>
    <CVE>CVE-2018-4361</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4361.html</URL>
        <Description>CVE-2018-4361</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110279</URL>
        <Description>SUSE Bug 1110279</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="37">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.</Note>
    </Notes>
    <CVE>CVE-2018-4372</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4372.html</URL>
        <Description>CVE-2018-4372</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1116998</URL>
        <Description>SUSE Bug 1116998</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="38">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.</Note>
    </Notes>
    <CVE>CVE-2018-4373</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4373.html</URL>
        <Description>CVE-2018-4373</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1116998</URL>
        <Description>SUSE Bug 1116998</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="39">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.</Note>
    </Notes>
    <CVE>CVE-2018-4375</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4375.html</URL>
        <Description>CVE-2018-4375</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1116998</URL>
        <Description>SUSE Bug 1116998</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="40">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.</Note>
    </Notes>
    <CVE>CVE-2018-4376</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4376.html</URL>
        <Description>CVE-2018-4376</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1116998</URL>
        <Description>SUSE Bug 1116998</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="41">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.</Note>
    </Notes>
    <CVE>CVE-2018-4378</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4378.html</URL>
        <Description>CVE-2018-4378</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1116998</URL>
        <Description>SUSE Bug 1116998</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="42">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.</Note>
    </Notes>
    <CVE>CVE-2018-4382</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4382.html</URL>
        <Description>CVE-2018-4382</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1116998</URL>
        <Description>SUSE Bug 1116998</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="43">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.</Note>
    </Notes>
    <CVE>CVE-2018-4386</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4386.html</URL>
        <Description>CVE-2018-4386</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1116998</URL>
        <Description>SUSE Bug 1116998</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="44">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.</Note>
    </Notes>
    <CVE>CVE-2018-4392</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4392.html</URL>
        <Description>CVE-2018-4392</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1116998</URL>
        <Description>SUSE Bug 1116998</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="45">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.</Note>
    </Notes>
    <CVE>CVE-2018-4416</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libjavascriptcoregtk-4_0-18-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk-4_0-37-32bit-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:libwebkit2gtk3-lang-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-JavaScriptCore-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:typelib-1_0-WebKit2WebExtension-4_0-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit-jsc-4-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk-4_0-injected-bundles-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-devel-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-minibrowser-2.22.4-15.1</ProductID>
        <ProductID>openSUSE Leap 42.3:webkit2gtk3-plugin-process-gtk2-2.22.4-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-01/msg00028.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-4416.html</URL>
        <Description>CVE-2018-4416</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1116998</URL>
        <Description>SUSE Bug 1116998</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
