2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20552 | — | — | 1.2% | Dec 28, 2018 | Tcpreplay before 4.3.1 has a heap-based buffer over-read in packet2tree in tree.c. |
| CVE-2018-20551 | — | — | 1.9% | Dec 28, 2018 | A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construct... |
| CVE-2018-20544 | — | — | 1.9% | Dec 28, 2018 | There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19. |
| CVE-2018-20543 | — | — | 1.0% | Dec 28, 2018 | There is an attempted excessive memory allocation at libxsmm_sparse_csc_reader in generator_spgemm_csc_reader.c in LIBXS... |
| CVE-2018-20542 | — | — | 1.9% | Dec 28, 2018 | There is a heap-based buffer-overflow at generator_spgemm_csc_reader.c (function libxsmm_sparse_csc_reader) in LIBXSMM 1... |
| CVE-2018-20541 | — | — | 1.9% | Dec 28, 2018 | There is a heap-based buffer overflow in libxsmm_sparse_csc_reader at generator_spgemm_csc_reader.c in LIBXSMM 1.10, a d... |
| CVE-2018-20540 | — | — | 1.5% | Dec 28, 2018 | There is memory leak at liblas::Open (liblas/liblas.hpp) in libLAS 1.8.1. |
| CVE-2018-20539 | — | — | 1.4% | Dec 28, 2018 | There is a Segmentation fault triggered by illegal address access at liblas::SpatialReference::GetGTIF() (spatialreferen... |
| CVE-2018-20538 | — | — | 0.8% | Dec 28, 2018 | There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a ... |
| CVE-2018-20537 | — | — | 1.1% | Dec 28, 2018 | There is a NULL pointer dereference at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that w... |
| CVE-2018-20536 | — | — | 1.4% | Dec 28, 2018 | There is a heap-based buffer over-read at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 tha... |
| CVE-2018-20535 | — | — | 0.8% | Dec 28, 2018 | There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a ... |
| CVE-2018-20534 | — | — | 2.3% | Dec 28, 2018 | There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of s... |
| CVE-2018-20533 | — | — | 2.2% | Dec 28, 2018 | There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv thr... |
| CVE-2018-20532 | — | — | 2.1% | Dec 28, 2018 | There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 ... |
| CVE-2018-20530 | — | — | 0.5% | Dec 28, 2018 | PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a Profile field such as Company Address, a related issue to CVE... |
| CVE-2018-20528 | — | — | 1.0% | Dec 28, 2018 | JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter. |
| CVE-2018-17539 | — | — | 2.2% | Dec 28, 2018 | The BGP daemon (bgpd) in all IP Infusion ZebOS versions to 7.10.6 and all OcNOS versions to 1.3.3.145 allow remote attac... |
| CVE-2018-1000890 | — | — | 1.8% | Dec 28, 2018 | FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachme... |
| CVE-2018-1000889 | — | — | 1.5% | Dec 28, 2018 | Logisim Evolution version 2.14.3 and earlier contains an XML External Entity (XXE) vulnerability in Circuit file loading... |
| CVE-2018-1000888 | — | — | 18.3% | Dec 28, 2018 | PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are... |
| CVE-2018-1000887 | — | — | 0.7% | Dec 28, 2018 | Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an auth... |
| CVE-2018-1000631 | — | — | 2.3% | Dec 28, 2018 | Battelle V2I Hub 3.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to th... |
| CVE-2018-1000630 | — | — | 1.9% | Dec 28, 2018 | Battelle V2I Hub 2.5.1 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL ... |
| CVE-2018-1000629 | — | — | 1.3% | Dec 28, 2018 | Battelle V2I Hub 2.5.1 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by ap... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now