2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5883 | — | — | 0.2% | Jun 14, 2019 | Buffer overflow in WLAN driver event handlers due to improper validation of array index in Snapdragon Auto, Snapdragon C... |
| CVE-2018-3583 | — | — | 0.2% | Jun 14, 2019 | A buffer overflow can occur while processing an extscan hotlist event in Snapdragon Auto, Snapdragon Consumer Electronic... |
| CVE-2018-20655 | CRITICAL | 9.8 | 2.2% | Jun 14, 2019 | When receiving calls using WhatsApp for iOS, a missing size check when parsing a sender-provided packet allowed for a st... |
| CVE-2018-13919 | — | — | 0.2% | Jun 14, 2019 | Use-after-free vulnerability will occur if reset of the routing table encounters an invalid rule id while processing com... |
| CVE-2018-13911 | — | — | 1.0% | Jun 14, 2019 | Out of bounds memory read and access may lead to unexpected behavior in GNSS XTRA Parser in Snapdragon Auto, Snapdragon ... |
| CVE-2018-13910 | — | — | 0.2% | Jun 14, 2019 | Out-of-Bounds access in TZ due to invalid index calculated to check against DDR in Snapdragon Auto, Snapdragon Connectiv... |
| CVE-2018-13909 | — | — | 0.1% | Jun 14, 2019 | Metadata verification and partial hash system calls by bootloader may corrupt parallel hashing state in progress resulti... |
| CVE-2018-13908 | — | — | 0.2% | Jun 14, 2019 | Truncated access authentication token leads to weakened access control for stored secure application data in Snapdragon ... |
| CVE-2018-13907 | — | — | 0.7% | Jun 14, 2019 | While deserializing any key blob during key operations, buffer overflow could occur, exposing partial key information if... |
| CVE-2018-13906 | — | — | 0.7% | Jun 14, 2019 | The HMAC authenticating the message from QSEE is vulnerable to timing side channel analysis leading to potentially forge... |
| CVE-2018-13902 | — | — | 0.7% | Jun 14, 2019 | Out of bounds memory read and access due to improper array index validation may lead to unexpected behavior while decodi... |
| CVE-2018-13901 | — | — | 0.2% | Jun 14, 2019 | Due to missing permissions in Android Manifest file, Sensitive information disclosure issue can happen in PCI RCS app in... |
| CVE-2018-13898 | — | — | 0.7% | Jun 14, 2019 | Out-of-Bounds write due to incorrect array index check in PMIC in Snapdragon Auto, Snapdragon Compute, Snapdragon Consum... |
| CVE-2018-11955 | — | — | 0.8% | Jun 14, 2019 | Lack of check on length of reason-code fetched from payload may lead driver access the memory not allocated to the frame... |
| CVE-2018-11947 | — | — | 0.2% | Jun 14, 2019 | The txrx stats req might be double freed in the pdev detach when the host driver is unloading in Snapdragon Auto, Snapdr... |
| CVE-2018-11942 | — | — | 0.2% | Jun 14, 2019 | Failure to initialize the reserved memory which is sent to the firmware might lead to exposure of 1 byte of uninitialize... |
| CVE-2018-11939 | — | — | 0.2% | Jun 14, 2019 | Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT... |
| CVE-2018-11934 | — | — | 0.2% | Jun 14, 2019 | Possible out of bounds write due to improper input validation while processing DO_ACS vendor command in Snapdragon Auto,... |
| CVE-2018-11929 | — | — | 0.2% | Jun 14, 2019 | Lack of input validation in WLAN function can lead to potential heap overflow in Snapdragon Auto, Snapdragon Consumer IO... |
| CVE-2018-11819 | — | — | 0.2% | Jun 14, 2019 | Use after issue in WLAN function due to multiple ACS scan requests at a time in Snapdragon Auto, Snapdragon Consumer IOT... |
| CVE-2018-10947 | — | — | 0.4% | Jun 13, 2019 | An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the admin cookie is reset on... |
| CVE-2018-10946 | — | — | 0.5% | Jun 13, 2019 | An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arb... |
| CVE-2018-3702 | HIGH | 7.8 | 0.3% | Jun 13, 2019 | Improper permissions in the installer for the ITE Tech* Consumer Infrared Driver for Windows 10 versions before 5.4.3.0 ... |
| CVE-2018-12147 | — | — | 0.5% | Jun 13, 2019 | Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Service... |
| CVE-2018-20841 | — | — | 47.9% | Jun 11, 2019 | HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now