2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19638 | LOW | 2.2 | 0.4% | Mar 5, 2019 | In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have o... |
| CVE-2018-19637 | LOW | 2.8 | 0.5% | Mar 5, 2019 | Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite f... |
| CVE-2018-16866 | LOW | 3.3 | 1.1% | Jan 11, 2019 | An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon '... |
| CVE-2018-17957 | LOW | 3.4 | 0.4% | Dec 26, 2018 | The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwo... |
| CVE-2018-20405 | LOW | 2.7 | 0.8% | Dec 23, 2018 | BigTree 4.3 allows full path disclosure via authenticated admin/news/ input that triggers a syntax error. NOTE: This has... |
| CVE-2018-16883 | LOW | 2.5 | 0.4% | Dec 19, 2018 | sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uid... |
| CVE-2018-6707 | LOW | 3.7 | 0.3% | Dec 14, 2018 | Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5... |
| CVE-2018-15774 | LOW | 3.8 | 0.9% | Dec 13, 2018 | Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and... |
| CVE-2018-1804 | LOW | 3.7 | 0.9% | Dec 13, 2018 | IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set the secure attribute ... |
| CVE-2018-1485 | LOW | 3.1 | 1.0% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not renew a session variable after a successful auth... |
| CVE-2018-1484 | LOW | 3.7 | 1.0% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens... |
| CVE-2018-1481 | LOW | 3.7 | 1.2% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may ... |
| CVE-2018-5559 | LOW | 3.4 | 0.6% | Nov 28, 2018 | In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connecti... |
| CVE-2018-1842 | LOW | 3.6 | 0.3% | Nov 9, 2018 | IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verificati... |
| CVE-2018-16849 | LOW | 3.1 | 1.5% | Nov 2, 2018 | A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to d... |
| CVE-2018-1380 | LOW | 2.7 | 1.1% | Oct 29, 2018 | IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with C... |
| CVE-2018-15765 | LOW | 3.4 | 0.4% | Oct 18, 2018 | Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log f... |
| CVE-2018-3139 | LOW | 3.1 | 5.2% | Oct 17, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported version... |
| CVE-2018-3136 | LOW | 3.4 | 3.6% | Oct 17, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions ... |
| CVE-2018-16738 | LOW | 3.7 | 1.4% | Oct 10, 2018 | tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed i... |
| CVE-2018-12477 | LOW | 3.5 | 1.2% | Oct 9, 2018 | A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletio... |
| CVE-2018-1670 | LOW | 3.1 | 1.2% | Oct 4, 2018 | IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain ... |
| CVE-2018-1593 | LOW | 3.7 | 0.4% | Oct 2, 2018 | IBM Multi-Cloud Data Encryption (MDE) 2.1 could allow an unauthorized user to manipulate data due to missing file checks... |
| CVE-2018-1509 | LOW | 3.7 | 0.9% | Oct 2, 2018 | IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allo... |
| CVE-2018-12473 | LOW | 3.1 | 1.8% | Oct 2, 2018 | A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause a... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now