2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18478 | — | — | 1.6% | Oct 18, 2018 | Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web scri... |
| CVE-2018-5188 | — | — | 3.9% | Oct 18, 2018 | Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of me... |
| CVE-2018-5187 | — | — | 3.0% | Oct 18, 2018 | Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and... |
| CVE-2018-5186 | — | — | 2.2% | Oct 18, 2018 | Memory safety bugs present in Firefox 60. Some of these bugs showed evidence of memory corruption and we presume that wi... |
| CVE-2018-5156 | — | — | 3.8% | Oct 18, 2018 | A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurrin... |
| CVE-2018-12387 | — | — | 9.6% | Oct 18, 2018 | A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in t... |
| CVE-2018-12386 | — | — | 13.4% | Oct 18, 2018 | A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and writ... |
| CVE-2018-12385 | — | — | 0.4% | Oct 18, 2018 | A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache... |
| CVE-2018-12383 | — | — | 0.5% | Oct 18, 2018 | If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords... |
| CVE-2018-12382 | — | — | 1.7% | Oct 18, 2018 | The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to... |
| CVE-2018-12381 | — | — | 1.8% | Oct 18, 2018 | Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message... |
| CVE-2018-12379 | — | — | 0.4% | Oct 18, 2018 | When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be... |
| CVE-2018-12378 | — | — | 3.4% | Oct 18, 2018 | A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that i... |
| CVE-2018-12377 | — | — | 3.4% | Oct 18, 2018 | A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown ... |
| CVE-2018-12376 | — | — | 3.1% | Oct 18, 2018 | Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption a... |
| CVE-2018-12375 | — | — | 1.8% | Oct 18, 2018 | Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption and we presume that wi... |
| CVE-2018-12374 | — | — | 2.0% | Oct 18, 2018 | Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text i... |
| CVE-2018-12373 | — | — | 2.4% | Oct 18, 2018 | dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forwa... |
| CVE-2018-12372 | — | — | 2.5% | Oct 18, 2018 | Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/... |
| CVE-2018-12370 | — | — | 1.1% | Oct 18, 2018 | In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Re... |
| CVE-2018-12369 | — | — | 2.5% | Oct 18, 2018 | WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a mali... |
| CVE-2018-12368 | — | — | 4.8% | Oct 18, 2018 | Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have ... |
| CVE-2018-12367 | — | — | 2.0% | Oct 18, 2018 | In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ab... |
| CVE-2018-12366 | — | — | 3.2% | Oct 18, 2018 | An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a f... |
| CVE-2018-12365 | — | — | 3.2% | Oct 18, 2018 | A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now