2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9532 | — | — | 0.7% | Nov 14, 2018 | In ixheaacd_extract_frame_info_ld of ixheaacd_env_extr.c there is a possible out of bounds write due to a missing bounds... |
| CVE-2018-9531 | — | — | 1.1% | Nov 14, 2018 | In AudioSpecificConfig_Parse of tpdec_asc.cpp, there is a possible out-of-bounds write due to a missing bounds check. Th... |
| CVE-2018-9530 | — | — | 0.7% | Nov 14, 2018 | In ixheaacd_tns_ar_filter_dec of ixheaacd_aac_tns.c there is a possible out of bounds write due to a missing bounds chec... |
| CVE-2018-9529 | — | — | 0.7% | Nov 14, 2018 | In ixheaacd_individual_ch_stream of ixheaacd_channel.c there is a possible out of bounds write due to a missing bounds c... |
| CVE-2018-9528 | — | — | 0.7% | Nov 14, 2018 | In ixheaacd_over_lap_add1_armv8 of ixheaacd_overlap_add1.s there is a possible out of bounds write due to a missing boun... |
| CVE-2018-9527 | — | — | 1.2% | Nov 14, 2018 | In vorbis_book_decodev_set of codebook.c there is a possible out of bounds write due to missing bounds check. This could... |
| CVE-2018-9526 | — | — | 0.9% | Nov 14, 2018 | In device configuration data, there is an improperly configured setting. This could lead to remote disclosure of device ... |
| CVE-2018-9525 | — | — | 0.2% | Nov 14, 2018 | In the AndroidManifest.xml file defining the SliceBroadcastReceiver handler for com.android.settings.slice.action.WIFI_C... |
| CVE-2018-9524 | — | — | 0.2% | Nov 14, 2018 | In functionality implemented in System UI, there are insufficient protections implemented around overlay windows. This c... |
| CVE-2018-9523 | — | — | 0.2% | Nov 14, 2018 | In Parcel.writeMapInternal of Parcel.java, there is a possible parcel serialization/deserialization mismatch due to impr... |
| CVE-2018-9522 | — | — | 0.2% | Nov 14, 2018 | In the serialization functions of StatsLogEventWrapper.java, there is a possible out-of-bounds write due to unnecessary ... |
| CVE-2018-9521 | — | — | 1.5% | Nov 14, 2018 | In parseMPEGCCData of NuPlayer2CCDecoder.cpp, there is a possible out of bounds write due to an incorrect bounds check. ... |
| CVE-2018-9457 | — | — | 0.2% | Nov 14, 2018 | In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact information due to a... |
| CVE-2018-9347 | — | — | 0.8% | Nov 14, 2018 | In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infinite loop. This coul... |
| CVE-2018-15714 | — | — | 3.8% | Nov 14, 2018 | Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 par... |
| CVE-2018-15713 | — | — | 7.2% | Nov 14, 2018 | Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address ... |
| CVE-2018-15712 | — | — | 48.6% | Nov 14, 2018 | Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in ap... |
| CVE-2018-15711 | — | — | 36.0% | Nov 14, 2018 | Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The ... |
| CVE-2018-15710 | — | — | 44.1% | Nov 14, 2018 | Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php. |
| CVE-2018-15709 | — | — | 21.0% | Nov 14, 2018 | Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request. |
| CVE-2018-15708 | — | — | 89.4% | Nov 14, 2018 | Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r... |
| CVE-2018-6083 | — | — | 1.6% | Nov 14, 2018 | Failure to disallow PWA installation from CSP sandboxed pages in AppManifest in Google Chrome prior to 65.0.3325.146 all... |
| CVE-2018-6082 | — | — | 1.4% | Nov 14, 2018 | Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remot... |
| CVE-2018-6081 | — | — | 0.9% | Nov 14, 2018 | XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to... |
| CVE-2018-6080 | — | — | 1.4% | Nov 14, 2018 | Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who h... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now