2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18929 | HIGH | 8.8 | 1.1% | Oct 29, 2019 | The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator ... |
| CVE-2018-21028 | HIGH | 7.5 | 2.1% | Oct 11, 2019 | Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function. |
| CVE-2018-20582 | HIGH | 8.8 | 0.7% | Oct 11, 2019 | The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery. |
| CVE-2018-5744 | HIGH | 7.5 | 3.4% | Oct 9, 2019 | A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affe... |
| CVE-2018-5743 | HIGH | 7.5 | 6.4% | Oct 9, 2019 | By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of al... |
| CVE-2018-5732 | HIGH | 7.5 | 5.0% | Oct 9, 2019 | Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masqu... |
| CVE-2018-21023 | HIGH | 8.8 | 3.0% | Oct 8, 2019 | getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parame... |
| CVE-2018-21022 | HIGH | 8.8 | 1.8% | Oct 8, 2019 | makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parame... |
| CVE-2018-21021 | HIGH | 8.8 | 1.8% | Oct 8, 2019 | img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter. |
| CVE-2018-21020 | HIGH | 7.5 | 2.0% | Oct 8, 2019 | In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows att... |
| CVE-2018-11768 | HIGH | 7.5 | 6.6% | Oct 4, 2019 | In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group informa... |
| CVE-2018-16452 | HIGH | 7.5 | 4.1% | Oct 3, 2019 | The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion. |
| CVE-2018-16451 | HIGH | 7.5 | 4.1% | Oct 3, 2019 | The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE... |
| CVE-2018-16301 | HIGH | 7.8 | 0.6% | Oct 3, 2019 | The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger t... |
| CVE-2018-16300 | HIGH | 7.5 | 4.1% | Oct 3, 2019 | The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited rec... |
| CVE-2018-16230 | HIGH | 7.5 | 3.9% | Oct 3, 2019 | The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI). |
| CVE-2018-16229 | HIGH | 7.5 | 6.8% | Oct 3, 2019 | The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option(). |
| CVE-2018-16228 | HIGH | 7.5 | 3.7% | Oct 3, 2019 | The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix(). |
| CVE-2018-16227 | HIGH | 7.5 | 6.8% | Oct 3, 2019 | The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield. |
| CVE-2018-14882 | HIGH | 7.5 | 3.9% | Oct 3, 2019 | The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c. |
| CVE-2018-14881 | HIGH | 7.5 | 4.8% | Oct 3, 2019 | The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTA... |
| CVE-2018-14880 | HIGH | 7.5 | 5.3% | Oct 3, 2019 | The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr(). |
| CVE-2018-14879 | HIGH | 7 | 4.7% | Oct 3, 2019 | The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file(). |
| CVE-2018-14470 | HIGH | 7.5 | 4.0% | Oct 3, 2019 | The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2(). |
| CVE-2018-14469 | HIGH | 7.5 | 5.3% | Oct 3, 2019 | The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print(). |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now