2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9504 | — | — | 0.9% | Oct 2, 2018 | In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds write due to an incorrect bounds check. This... |
| CVE-2018-9503 | — | — | 2.6% | Oct 2, 2018 | In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out of bounds read due to a missing bounds check. Thi... |
| CVE-2018-9502 | — | — | 1.2% | Oct 2, 2018 | In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out-of-bounds read due to a missing bounds check. Thi... |
| CVE-2018-9501 | — | — | 0.2% | Oct 2, 2018 | In the SetupWizard, there is a possible Factory Reset Protection bypass due to a permissions bypass. This could lead to ... |
| CVE-2018-9499 | — | — | 0.3% | Oct 2, 2018 | In readVector of iCrypto.cpp, there is a possible invalid read due to uninitialized data. This could lead to local infor... |
| CVE-2018-9498 | — | — | 1.6% | Oct 2, 2018 | In SkSampler::Fill of SkSampler.cpp, there is a possible out of bounds write due to an integer overflow. This could lead... |
| CVE-2018-9497 | — | — | 1.6% | Oct 2, 2018 | In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv_av8 of impeg2_format_conv.s there is a possible out of bounds write due to mis... |
| CVE-2018-9496 | — | — | 1.8% | Oct 2, 2018 | In ixheaacd_real_synth_fft_p3 of ixheaacd_esbr_fft.c there is a possible out of bounds write due to a missing bounds che... |
| CVE-2018-9493 | — | — | 0.9% | Oct 2, 2018 | In the content provider of the download manager, there is a possible SQL injection due to improper input validation. Thi... |
| CVE-2018-9492 | — | — | 0.2% | Oct 2, 2018 | In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead... |
| CVE-2018-9491 | — | — | 1.5% | Oct 2, 2018 | In AMediaCodecCryptoInfo_new of NdkMediaCodec.cpp, there is a possible out-of-bounds write due to an integer overflow. T... |
| CVE-2018-9490 | — | — | 1.4% | Oct 2, 2018 | In CollectValuesOrEntriesImpl of elements.cc, there is possible remote code execution due to type confusion. This could ... |
| CVE-2018-9476 | — | — | 2.5% | Oct 2, 2018 | In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible use-after-free due to improper locking. This could lea... |
| CVE-2018-9473 | — | — | 1.5% | Oct 2, 2018 | In ihevcd_parse_sei_payload of ihevcd_parse_headers.c, there is a possible out-of-bounds write due to an integer overflo... |
| CVE-2018-9452 | — | — | 0.9% | Oct 2, 2018 | In getOffsetForHorizontal of Layout.java, there is a possible application hang due to a slow width calculation. This cou... |
| CVE-2018-11750 | — | — | 1.1% | Oct 2, 2018 | Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As... |
| CVE-2018-11748 | — | — | 0.3% | Oct 2, 2018 | Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world ... |
| CVE-2018-17886 | — | — | 0.7% | Oct 2, 2018 | An issue was discovered in JEESNS 1.3. The XSS filter in com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java ... |
| CVE-2018-17884 | — | — | 1.2% | Oct 2, 2018 | XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via th... |
| CVE-2018-17787 | — | — | 3.7% | Oct 2, 2018 | On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the PO... |
| CVE-2018-17786 | — | — | 4.1% | Oct 2, 2018 | On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not... |
| CVE-2018-17596 | — | — | 2.3% | Oct 2, 2018 | In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ... |
| CVE-2018-17595 | — | — | 1.0% | Oct 2, 2018 | In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /ba... |
| CVE-2018-17594 | — | — | 1.0% | Oct 2, 2018 | AirTies Air 5443v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-17593 | — | — | 2.3% | Oct 2, 2018 | AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now