A bug in JSC YarrJIT initParenContextFreeList allows for bytes to be overwritten.
038399bf2390bfa66637b2a2feb687184873772e215bfdc1e773cfc1d47d7c58
OpenSSL Security Advisory 20190730 - OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used for verification in TLS. This directory is most commonly referred to as OPENSSLDIR, and is configurable with the --prefix / --openssldir configuration options.
da7079548b0a5591209ceeed88dc0406ec0810078f33f7b84a7e2cbbe5c9f7be
JSC suffers from a data mishandling bug in ytecodeGenerator::emitEqualityOpImpl.
8bea8fb18d0ac7ce60485d227dcad33f12182219301a7157fc251e6f00c07bfb