2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18506 | MEDIUM | 5.9 | 2.2% | Feb 5, 2019 | When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is l... |
| CVE-2018-18505 | — | — | 4.5% | Feb 5, 2019 | An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communicat... |
| CVE-2018-18504 | — | — | 1.8% | Feb 5, 2019 | A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during gr... |
| CVE-2018-18503 | — | — | 1.4% | Feb 5, 2019 | When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a... |
| CVE-2018-18502 | — | — | 2.2% | Feb 5, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed ev... |
| CVE-2018-18501 | — | — | 3.5% | Feb 5, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of... |
| CVE-2018-18500 | — | — | 12.7% | Feb 5, 2019 | A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This result... |
| CVE-2018-8800 | CRITICAL | 9.8 | 7.1% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that... |
| CVE-2018-8799 | — | — | 4.1% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that re... |
| CVE-2018-8798 | — | — | 3.8% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that result... |
| CVE-2018-8797 | CRITICAL | 9.8 | 7.1% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that resul... |
| CVE-2018-8796 | — | — | 4.1% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that res... |
| CVE-2018-8795 | CRITICAL | 9.8 | 7.4% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in f... |
| CVE-2018-8794 | CRITICAL | 9.8 | 6.7% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in functio... |
| CVE-2018-8793 | CRITICAL | 9.8 | 7.1% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that... |
| CVE-2018-8792 | — | — | 4.1% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that result... |
| CVE-2018-8791 | — | — | 3.8% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in a... |
| CVE-2018-20252 | — | — | 3.6% | Feb 5, 2019 | In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ... |
| CVE-2018-20251 | — | — | 31.5% | Feb 5, 2019 | In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field o... |
| CVE-2018-20250 | HIGH | 7.8 | 96.3% | Feb 5, 2019 | In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o... |
| CVE-2018-4056 | CRITICAL | 9.8 | 3.0% | Feb 5, 2019 | An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.... |
| CVE-2018-19029 | — | — | 2.7% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a poin... |
| CVE-2018-19002 | — | — | 2.7% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially cra... |
| CVE-2018-19000 | — | — | 8.8% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sen... |
| CVE-2018-18998 | — | — | 2.4% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized acce... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now