2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20799 | — | — | 1.6% | Mar 1, 2019 | In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blo... |
| CVE-2018-20798 | — | — | 1.4% | Mar 1, 2019 | The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durati... |
| CVE-2018-18499 | — | — | 1.1% | Feb 28, 2019 | A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on ... |
| CVE-2018-18498 | — | — | 4.0% | Feb 28, 2019 | A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw... |
| CVE-2018-18497 | — | — | 1.4% | Feb 28, 2019 | Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the UR... |
| CVE-2018-18496 | — | — | 1.2% | Feb 28, 2019 | When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted conten... |
| CVE-2018-18495 | — | — | 1.7% | Feb 28, 2019 | WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions gran... |
| CVE-2018-18494 | — | — | 1.5% | Feb 28, 2019 | A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location propert... |
| CVE-2018-18493 | — | — | 5.0% | Feb 28, 2019 | A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D ac... |
| CVE-2018-18492 | — | — | 9.6% | Feb 28, 2019 | A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select elemen... |
| CVE-2018-12407 | — | — | 3.3% | Feb 28, 2019 | A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, w... |
| CVE-2018-12406 | — | — | 1.1% | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed ev... |
| CVE-2018-12405 | — | — | 3.2% | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of... |
| CVE-2018-12403 | — | — | 1.9% | Feb 28, 2019 | If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not dis... |
| CVE-2018-12402 | — | — | 1.4% | Feb 28, 2019 | The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when ... |
| CVE-2018-12401 | — | — | 2.3% | Feb 28, 2019 | Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the ... |
| CVE-2018-12400 | — | — | 1.6% | Feb 28, 2019 | In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-privat... |
| CVE-2018-12399 | — | — | 1.4% | Feb 28, 2019 | When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about whi... |
| CVE-2018-12398 | — | — | 1.6% | Feb 28, 2019 | By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypa... |
| CVE-2018-12397 | — | — | 0.4% | Feb 28, 2019 | A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your... |
| CVE-2018-12396 | — | — | 2.3% | Feb 28, 2019 | A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events... |
| CVE-2018-12395 | — | — | 2.9% | Feb 28, 2019 | By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through d... |
| CVE-2018-12393 | — | — | 3.9% | Feb 28, 2019 | A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an in... |
| CVE-2018-12392 | — | — | 3.4% | Feb 28, 2019 | When manipulating user events in nested loops while opening a document through script, it is possible to trigger a poten... |
| CVE-2018-12391 | — | — | 2.1% | Feb 28, 2019 | During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of secur... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now