2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19908 | — | — | 17.2% | Dec 6, 2018 | An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped file... |
| CVE-2018-9568 | HIGH | 7.8 | 0.7% | Dec 6, 2018 | In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escala... |
| CVE-2018-9567 | — | — | 0.1% | Dec 6, 2018 | On Pixel devices there is a bug causing verified boot to show the same certificate fingerprint despite using different s... |
| CVE-2018-9566 | MEDIUM | 5.7 | 0.4% | Dec 6, 2018 | In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a missing bounds check. ... |
| CVE-2018-9565 | HIGH | 7.5 | 1.1% | Dec 6, 2018 | In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to rem... |
| CVE-2018-9562 | HIGH | 7.5 | 1.1% | Dec 6, 2018 | In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parameter size. This could... |
| CVE-2018-9560 | HIGH | 7.8 | 0.2% | Dec 6, 2018 | In HID_DevAddRecord of hidd_api.cc, there is a possible out-of-bounds write due to a missing bounds check. This could le... |
| CVE-2018-9559 | — | — | 0.2% | Dec 6, 2018 | In persist_set_key and other functions of cryptfs.cpp, there is a possible out-of-bounds write due to an uncaught error.... |
| CVE-2018-9558 | HIGH | 7.8 | 0.2% | Dec 6, 2018 | In rw_t2t_handle_tlv_detect of rw_t2t_ndef.cc, there is a possible out-of-bounds write due to a missing bounds check. Th... |
| CVE-2018-9557 | — | — | 0.2% | Dec 6, 2018 | In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninitialized data. This c... |
| CVE-2018-9556 | CRITICAL | 9.8 | 2.0% | Dec 6, 2018 | In ParsePayloadHeader of payload_metadata.cc, there is a possible out of bounds write due to an integer overflow. This c... |
| CVE-2018-9555 | HIGH | 8.8 | 0.7% | Dec 6, 2018 | In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lea... |
| CVE-2018-9554 | — | — | 0.2% | Dec 6, 2018 | In dumpExtractors of IMediaExtractor.cp, there is a possible disclosure of recently accessed media files due to a permis... |
| CVE-2018-9553 | HIGH | 7.8 | 1.1% | Dec 6, 2018 | In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure default value. This could... |
| CVE-2018-9552 | MEDIUM | 5.5 | 0.5% | Dec 6, 2018 | In ihevcd_sao_shift_ctb of ihevcd_sao.c there is a possible out of bounds write due to missing bounds check. This could ... |
| CVE-2018-9551 | HIGH | 7.8 | 1.1% | Dec 6, 2018 | In CAacDecoder_Init of aacdecoder.cpp, there is a possible out-of-bound write due to a missing bounds check. This could ... |
| CVE-2018-9550 | HIGH | 7.8 | 1.2% | Dec 6, 2018 | In CAacDecoder_Init of aacdecoder.cpp, there is a possible out of bounds write due to a missing bounds check. This could... |
| CVE-2018-9549 | HIGH | 7.8 | 1.1% | Dec 6, 2018 | In lppTransposer of lpp_tran.cpp there is a possible out of bounds write due to missing bounds check. This could lead to... |
| CVE-2018-9548 | MEDIUM | 5.5 | 0.2% | Dec 6, 2018 | In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missing URI validation. Th... |
| CVE-2018-9547 | HIGH | 7.8 | 0.2% | Dec 6, 2018 | In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to... |
| CVE-2018-9538 | HIGH | 7.8 | 0.2% | Dec 6, 2018 | In V4L2SliceVideoDecodeAccelerator::Dequeue of v4l2_slice_video_decode_accelerator.cc, there is a possible out of bounds... |
| CVE-2018-1935 | MEDIUM | 4.3 | 1.3% | Dec 6, 2018 | IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request... |
| CVE-2018-1871 | MEDIUM | 5.4 | 1.0% | Dec 6, 2018 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross... |
| CVE-2018-1525 | MEDIUM | 5.9 | 1.1% | Dec 6, 2018 | IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the fa... |
| CVE-2018-1505 | MEDIUM | 4 | 0.4% | Dec 6, 2018 | IBM i2 Enterprise Insight Analysis 2.1.7 allows web pages to be stored locally which can be read by another user on the ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now