2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19624 | — | — | 1.4% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/p... |
| CVE-2018-19623 | — | — | 4.2% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could crash. In addition, a remote attacker could ... |
| CVE-2018-19622 | — | — | 3.2% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed i... |
| CVE-2018-18203 | — | — | 0.2% | Nov 28, 2018 | A vulnerability in the update mechanism of Subaru StarLink Harman head units 2017, 2018, and 2019 may give an attacker (... |
| CVE-2018-19651 | — | — | 0.8% | Nov 28, 2018 | admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=... |
| CVE-2018-19370 | — | — | 3.2% | Nov 28, 2018 | A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) ... |
| CVE-2018-19646 | — | — | 3.5% | Nov 28, 2018 | The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute ar... |
| CVE-2018-17156 | — | — | 1.6% | Nov 28, 2018 | In FreeBSD before 11.2-STABLE(r340268) and 11.2-RELEASE-p5, due to incorrectly accounting for padding on 64-bit platform... |
| CVE-2018-14749 | — | — | 1.2% | Nov 28, 2018 | Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6... |
| CVE-2018-14748 | — | — | 1.3% | Nov 28, 2018 | Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QT... |
| CVE-2018-14747 | — | — | 1.3% | Nov 28, 2018 | NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, ... |
| CVE-2018-14746 | — | — | 3.3% | Nov 28, 2018 | Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2... |
| CVE-2018-5918 | — | — | 0.2% | Nov 28, 2018 | Possible buffer overflow in DRM Trusted application due to lack of check function return values in Snapdragon Automobile... |
| CVE-2018-5917 | — | — | 0.3% | Nov 28, 2018 | Possible buffer overflow in OEM crypto function due to improper input validation in Snapdragon Automobile, Snapdragon Mo... |
| CVE-2018-5916 | — | — | 0.4% | Nov 28, 2018 | Buffer overread while decoding PDP modify request or network initiated secondary PDP activation in Snapdragon Automobile... |
| CVE-2018-5912 | — | — | 0.2% | Nov 28, 2018 | Potential buffer overflow in Video due to lack of input validation in input and output values in Snapdragon Automobile, ... |
| CVE-2018-5877 | — | — | 0.2% | Nov 28, 2018 | In the device programmer target-side code for firehose, a string may not be properly NULL terminated can lead to a incor... |
| CVE-2018-5870 | — | — | 0.2% | Nov 28, 2018 | While loading a service image, an untrusted pointer dereference can occur in Snapdragon Mobile in versions SD 835, SDA66... |
| CVE-2018-11996 | — | — | 0.2% | Nov 28, 2018 | When a malformed command is sent to the device programmer, an out-of-bounds access can occur in Snapdragon Automobile, S... |
| CVE-2018-11994 | — | — | 0.2% | Nov 28, 2018 | SMMU secure camera logic allows secure camera controllers to access HLOS memory during session in Snapdragon Automobile,... |
| CVE-2018-11921 | — | — | 0.2% | Nov 28, 2018 | Failure condition is not handled properly and the correct error code is not returned. It could cause unintended SUI beha... |
| CVE-2018-11264 | — | — | 0.2% | Nov 28, 2018 | Possible buffer overflow in Ontario fingerprint code due to lack of input validation for the parameters coming into TZ f... |
| CVE-2018-19630 | — | — | 0.7% | Nov 28, 2018 | cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the... |
| CVE-2018-19621 | — | — | 0.4% | Nov 28, 2018 | server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team. |
| CVE-2018-19620 | — | — | 1.3% | Nov 28, 2018 | ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now