2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11854 | — | — | 0.2% | Oct 26, 2018 | Lack of check of valid length of input parameter may cause buffer overwrite in WLAN in Snapdragon Mobile in version SD 8... |
| CVE-2018-11853 | — | — | 0.2% | Oct 26, 2018 | Lack of check on out of range for channels When processing channel list set command will lead to buffer flow in Snapdrag... |
| CVE-2018-11850 | — | — | 0.2% | Oct 26, 2018 | Lack of check on remaining length parameter When processing scan start command will lead to buffer flow in Snapdragon Au... |
| CVE-2018-11849 | — | — | 0.2% | Oct 26, 2018 | Lack of check on out of range of bssid parameter When processing scan start command will lead to buffer flow in Snapdrag... |
| CVE-2018-11846 | — | — | 0.2% | Oct 26, 2018 | The use of a non-time-constant memory comparison operation can lead to timing/side channel attacks in Snapdragon Mobile ... |
| CVE-2018-11828 | — | — | 1.1% | Oct 26, 2018 | When FW tries to get random mac address generated from new SW RNG and ADC values read are constant then DUT get struck i... |
| CVE-2018-11824 | — | — | 0.2% | Oct 26, 2018 | A stack-based buffer overflow can occur in a firmware routine in Snapdragon Mobile, Snapdragon Wear in version MDM9206, ... |
| CVE-2018-11822 | — | — | 0.2% | Oct 26, 2018 | A possible integer overflow may happen in WLAN during memory allocation in Snapdragon Mobile in version SD 835, SD 845, ... |
| CVE-2018-11821 | — | — | 0.2% | Oct 26, 2018 | Possible integer overflow may happen in WLAN during memory allocation in Snapdragon Mobile, Snapdragon Wear in version I... |
| CVE-2018-11305 | — | — | 0.3% | Oct 26, 2018 | When a series of FDAL messages are sent to the modem, a Use After Free condition can occur in Snapdragon Automobile, Sna... |
| CVE-2018-18656 | — | — | 0.4% | Oct 26, 2018 | The PureVPN client before 6.1.0 for Windows stores Login Credentials (username and password) in cleartext. The location ... |
| CVE-2018-18655 | — | — | 0.8% | Oct 26, 2018 | Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email b... |
| CVE-2018-18654 | — | — | 0.3% | Oct 26, 2018 | Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a wo... |
| CVE-2018-18653 | — | — | 0.3% | Oct 26, 2018 | The Linux kernel, as used in Ubuntu 18.10 and when booted with UEFI Secure Boot enabled, allows privileged local users t... |
| CVE-2018-18652 | — | — | 4.1% | Oct 25, 2018 | A remote command execution vulnerability in Veritas NetBackup Appliance before 3.1.2 allows authenticated administrators... |
| CVE-2018-17904 | — | — | 0.9% | Oct 25, 2018 | Reliance 4 SCADA/HMI, Version 4.7.3 Update 3 and prior. This vulnerability could allow an unauthorized attacker to injec... |
| CVE-2018-14665 | — | — | 27.0% | Oct 25, 2018 | A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh... |
| CVE-2018-18651 | — | — | 0.9% | Oct 25, 2018 | An issue was discovered in Xpdf 4.00. catalog->getNumPages() in AcroForm.cc allows attackers to launch a denial of servi... |
| CVE-2018-18650 | — | — | 0.9% | Oct 25, 2018 | An issue was discovered in Xpdf 4.00. XRef::readXRefStream in XRef.cc allows attackers to launch a denial of service (In... |
| CVE-2018-8955 | — | — | 4.3% | Oct 24, 2018 | The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installatio... |
| CVE-2018-18638 | — | — | 2.8% | Oct 24, 2018 | A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execu... |
| CVE-2018-18621 | — | — | 1.1% | Oct 24, 2018 | CommuniGate Pro 6.2 allows stored XSS via a message body in Pronto! Mail Composer, which is mishandled in /MIME/INBOX-MM... |
| CVE-2018-18567 | — | — | 1.2% | Oct 24, 2018 | AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credentia... |
| CVE-2018-18552 | — | — | 2.7% | Oct 24, 2018 | ServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss... |
| CVE-2018-18551 | — | — | 1.1% | Oct 24, 2018 | ServersCheck Monitoring Software through 14.3.3 has Persistent and Reflected XSS via the sensors.html status parameter, ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now