2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6135 | — | — | 1.4% | Jan 9, 2019 | Lack of clearing the previous site before loading alerts from a new one in Blink in Google Chrome prior to 67.0.3396.62 ... |
| CVE-2018-6133 | — | — | 1.4% | Jan 9, 2019 | Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 67.0.3396.62 allowed a remote att... |
| CVE-2018-6127 | — | — | 1.8% | Jan 9, 2019 | Early free of object in use in IndexDB in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromi... |
| CVE-2018-6126 | — | — | 7.7% | Jan 9, 2019 | A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds m... |
| CVE-2018-6124 | — | — | 1.9% | Jan 9, 2019 | Type confusion in ReadableStreams in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potential... |
| CVE-2018-6123 | — | — | 1.9% | Jan 9, 2019 | A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap c... |
| CVE-2018-6120 | — | — | 2.4% | Jan 9, 2019 | An integer overflow that could lead to an attacker-controlled heap out-of-bounds write in PDFium in Google Chrome prior ... |
| CVE-2018-6117 | — | — | 1.9% | Jan 9, 2019 | Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially s... |
| CVE-2018-6114 | — | — | 1.5% | Jan 9, 2019 | Incorrect enforcement of CSP for <object> tags in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacke... |
| CVE-2018-6113 | — | — | 1.5% | Jan 9, 2019 | Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a r... |
| CVE-2018-6112 | — | — | 1.6% | Jan 9, 2019 | Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remot... |
| CVE-2018-6111 | — | — | 2.6% | Jan 9, 2019 | An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local ... |
| CVE-2018-6110 | — | — | 1.2% | Jan 9, 2019 | Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome... |
| CVE-2018-6109 | — | — | 1.4% | Jan 9, 2019 | readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in ... |
| CVE-2018-6106 | — | — | 1.7% | Jan 9, 2019 | An asynchronous generator may return an incorrect state in V8 in Google Chrome prior to 66.0.3359.117 allowing a remote ... |
| CVE-2018-6100 | — | — | 1.4% | Jan 9, 2019 | Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a ... |
| CVE-2018-6097 | — | — | 1.5% | Jan 9, 2019 | Incorrect handling of asynchronous methods in Fullscreen in Google Chrome on macOS prior to 66.0.3359.117 allowed a remo... |
| CVE-2018-6096 | — | — | 1.5% | Jan 9, 2019 | A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.... |
| CVE-2018-6093 | — | — | 1.6% | Jan 9, 2019 | Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-orig... |
| CVE-2018-6091 | — | — | 2.1% | Jan 9, 2019 | Service Workers can intercept any request made by an <embed> or <object> tag in Fetch API in Google Chrome prior to 66.0... |
| CVE-2018-6084 | — | — | 1.1% | Jan 9, 2019 | Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local... |
| CVE-2018-6056 | — | — | 8.8% | Jan 9, 2019 | Type confusion could lead to a heap out-of-bounds write in V8 in Google Chrome prior to 64.0.3282.168 allowing a remote ... |
| CVE-2018-20071 | — | — | 0.4% | Jan 9, 2019 | Insufficiently strict origin checks during JIT payment app installation in Payments in Google Chrome prior to 70.0.3538.... |
| CVE-2018-20070 | — | — | 0.5% | Jan 9, 2019 | Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote att... |
| CVE-2018-20069 | — | — | 0.4% | Jan 9, 2019 | Failure to prevent navigation to top frame to data URLs in Navigation in Google Chrome on iOS prior to 71.0.3578.80 allo... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now