2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-9532In ixheaacd_extract_frame_info_ld of ixheaacd_env_extr.c there is a possible out of bounds write due to a missing bounds...
CVE-2018-9531In AudioSpecificConfig_Parse of tpdec_asc.cpp, there is a possible out-of-bounds write due to a missing bounds check. Th...
CVE-2018-9530In ixheaacd_tns_ar_filter_dec of ixheaacd_aac_tns.c there is a possible out of bounds write due to a missing bounds chec...
CVE-2018-9529In ixheaacd_individual_ch_stream of ixheaacd_channel.c there is a possible out of bounds write due to a missing bounds c...
CVE-2018-9528In ixheaacd_over_lap_add1_armv8 of ixheaacd_overlap_add1.s there is a possible out of bounds write due to a missing boun...
CVE-2018-9527In vorbis_book_decodev_set of codebook.c there is a possible out of bounds write due to missing bounds check. This could...
CVE-2018-9526In device configuration data, there is an improperly configured setting. This could lead to remote disclosure of device ...
CVE-2018-9525In the AndroidManifest.xml file defining the SliceBroadcastReceiver handler for com.android.settings.slice.action.WIFI_C...
CVE-2018-9524In functionality implemented in System UI, there are insufficient protections implemented around overlay windows. This c...
CVE-2018-9523In Parcel.writeMapInternal of Parcel.java, there is a possible parcel serialization/deserialization mismatch due to impr...
CVE-2018-9522In the serialization functions of StatsLogEventWrapper.java, there is a possible out-of-bounds write due to unnecessary ...
CVE-2018-9521In parseMPEGCCData of NuPlayer2CCDecoder.cpp, there is a possible out of bounds write due to an incorrect bounds check. ...
CVE-2018-9457In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact information due to a...
CVE-2018-9347In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infinite loop. This coul...
CVE-2018-15714Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 par...
CVE-2018-15713Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address ...
CVE-2018-15712Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in ap...
CVE-2018-15711Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The ...
CVE-2018-15710Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
CVE-2018-15709Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.
CVE-2018-15708Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r...
CVE-2018-6083Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 all...
CVE-2018-6082Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remot...
CVE-2018-6081XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to...
CVE-2018-6080Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who h...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now