2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-4448 | MEDIUM | 5.5 | 0.3% | Oct 27, 2020 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.4, ... |
| CVE-2018-4444 | MEDIUM | 6.5 | 1.1% | Oct 27, 2020 | A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.... |
| CVE-2018-4433 | MEDIUM | 5.5 | 0.7% | Oct 27, 2020 | A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Mojave 10.14.4, Security ... |
| CVE-2018-4391 | MEDIUM | 5.5 | 0.9% | Oct 27, 2020 | An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sie... |
| CVE-2018-4390 | MEDIUM | 5.5 | 0.9% | Oct 27, 2020 | An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sie... |
| CVE-2018-4381 | MEDIUM | 5.5 | 0.6% | Oct 27, 2020 | A resource exhaustion issue was addressed with improved input validation. This issue is fixed in tvOS 12.1, iOS 12.1. Pr... |
| CVE-2018-4339 | MEDIUM | 5.5 | 0.3% | Oct 27, 2020 | This issue was addressed with a new entitlement. This issue is fixed in iOS 12.1. A local user may be able to read a per... |
| CVE-2018-21269 | MEDIUM | 5.5 | 0.4% | Oct 27, 2020 | checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal p... |
| CVE-2018-8062 | MEDIUM | 5.4 | 1.0% | Oct 23, 2020 | A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware... |
| CVE-2018-18508 | MEDIUM | 6.5 | 2.0% | Oct 22, 2020 | In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a nul... |
| CVE-2018-6449 | MEDIUM | 6.1 | 0.8% | Sep 25, 2020 | Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could a... |
| CVE-2018-6447 | MEDIUM | 5.4 | 0.5% | Sep 25, 2020 | A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.... |
| CVE-2018-19948 | MEDIUM | 6.5 | 0.3% | Sep 11, 2020 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forge... |
| CVE-2018-19947 | MEDIUM | 6.5 | 0.8% | Sep 11, 2020 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vul... |
| CVE-2018-19946 | MEDIUM | 5.9 | 0.3% | Sep 11, 2020 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate val... |
| CVE-2018-17774 | MEDIUM | 6.8 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have an insecure NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N. |
| CVE-2018-17773 | MEDIUM | 6.8 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have a buffer overflow via SOCKET_TASK in the NTPT3 protocol. This is fixed in Telium 2 ... |
| CVE-2018-17772 | MEDIUM | 6.8 | 0.7% | Sep 9, 2020 | Ingenico Telium 2 POS terminals allow arbitrary code execution via the TRACE protocol. This is fixed in Telium 2 SDK v9.... |
| CVE-2018-17771 | MEDIUM | 6.6 | 0.5% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N. |
| CVE-2018-17770 | MEDIUM | 6.6 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have a buffer overflow via the RemotePutFile command of the NTPT3 protocol. This is fixe... |
| CVE-2018-17769 | MEDIUM | 6.6 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have a buffer overflow via the 0x26 command of the NTPT3 protocol. This is fixed in Teli... |
| CVE-2018-17768 | MEDIUM | 6.8 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have an insecure TRACE protocol. This is fixed in Telium 2 SDK v9.32.03 patch N. |
| CVE-2018-17767 | MEDIUM | 6.8 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N. |
| CVE-2018-17766 | MEDIUM | 4.6 | 0.5% | Sep 9, 2020 | Ingenico Telium 2 POS Telium2 OS allow bypass of file-reading restrictions via the NTPT3 protocol. This is fixed in Teli... |
| CVE-2018-17765 | MEDIUM | 6.8 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have undeclared TRACE protocol commands. This is fixed in Telium 2 SDK v9.32.03 patch N. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now