2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-6135——Lack of clearing the previous site before loading alerts from a new one in Blink in Google Chrome prior to 67.0.3396.62 ...
CVE-2018-6133——Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 67.0.3396.62 allowed a remote att...
CVE-2018-6127——Early free of object in use in IndexDB in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromi...
CVE-2018-6126——A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds m...
CVE-2018-6124——Type confusion in ReadableStreams in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potential...
CVE-2018-6123——A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap c...
CVE-2018-6120——An integer overflow that could lead to an attacker-controlled heap out-of-bounds write in PDFium in Google Chrome prior ...
CVE-2018-6117——Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially s...
CVE-2018-6114——Incorrect enforcement of CSP for <object> tags in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacke...
CVE-2018-6113——Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a r...
CVE-2018-6112——Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remot...
CVE-2018-6111——An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local ...
CVE-2018-6110——Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome...
CVE-2018-6109——readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in ...
CVE-2018-6106——An asynchronous generator may return an incorrect state in V8 in Google Chrome prior to 66.0.3359.117 allowing a remote ...
CVE-2018-6100——Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a ...
CVE-2018-6097——Incorrect handling of asynchronous methods in Fullscreen in Google Chrome on macOS prior to 66.0.3359.117 allowed a remo...
CVE-2018-6096——A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359....
CVE-2018-6093——Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-orig...
CVE-2018-6091——Service Workers can intercept any request made by an <embed> or <object> tag in Fetch API in Google Chrome prior to 66.0...
CVE-2018-6084——Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local...
CVE-2018-6056——Type confusion could lead to a heap out-of-bounds write in V8 in Google Chrome prior to 64.0.3282.168 allowing a remote ...
CVE-2018-20071——Insufficiently strict origin checks during JIT payment app installation in Payments in Google Chrome prior to 70.0.3538....
CVE-2018-20070——Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote att...
CVE-2018-20069——Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71.0.3578.80 allo...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now