2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17950 | — | — | 0.8% | Dec 12, 2018 | Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2 |
| CVE-2018-17949 | — | — | 0.6% | Dec 12, 2018 | Cross site scripting vulnerability in iManager prior to 3.1 SP2. |
| CVE-2018-15328 | — | — | 2.3% | Dec 12, 2018 | On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passp... |
| CVE-2018-20099 | — | — | 2.3% | Dec 12, 2018 | There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will le... |
| CVE-2018-20098 | — | — | 2.6% | Dec 12, 2018 | There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted ... |
| CVE-2018-20096 | — | — | 2.8% | Dec 12, 2018 | There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted... |
| CVE-2018-20095 | — | — | 1.2% | Dec 12, 2018 | An issue was discovered in EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input triggers an attempt ... |
| CVE-2018-20094 | — | — | 1.8% | Dec 12, 2018 | An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that ca... |
| CVE-2018-18397 | — | — | 0.5% | Dec 12, 2018 | The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl cal... |
| CVE-2018-8652 | — | — | 1.5% | Dec 12, 2018 | A Cross-site Scripting (XSS) vulnerability exists when Windows Azure Pack does not properly sanitize user-provided input... |
| CVE-2018-8651 | — | — | 1.5% | Dec 12, 2018 | A cross site scripting vulnerability exists when Microsoft Dynamics NAV does not properly sanitize a specially crafted w... |
| CVE-2018-8649 | — | — | 1.7% | Dec 12, 2018 | A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Servi... |
| CVE-2018-8643 | — | — | 9.9% | Dec 12, 2018 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ... |
| CVE-2018-8641 | — | — | 1.1% | Dec 12, 2018 | An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o... |
| CVE-2018-8638 | — | — | 1.8% | Dec 12, 2018 | An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Informati... |
| CVE-2018-8637 | — | — | 1.8% | Dec 12, 2018 | An information disclosure vulnerability exists in Windows kernel that could allow an attacker to retrieve information th... |
| CVE-2018-8636 | — | — | 16.2% | Dec 12, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2018-8635 | — | — | 6.1% | Dec 12, 2018 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c... |
| CVE-2018-8634 | — | — | 14.5% | Dec 12, 2018 | A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to properly handle objects ... |
| CVE-2018-8631 | — | — | 69.2% | Dec 12, 2018 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet... |
| CVE-2018-8629 | — | — | 23.2% | Dec 12, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8628 | — | — | 16.2% | Dec 12, 2018 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle... |
| CVE-2018-8627 | — | — | 8.7% | Dec 12, 2018 | An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uniniti... |
| CVE-2018-8626 | — | — | 21.1% | Dec 12, 2018 | A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly hand... |
| CVE-2018-8625 | — | — | 43.8% | Dec 12, 2018 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now