2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-9504In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds write due to an incorrect bounds check. This...
CVE-2018-9503In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out of bounds read due to a missing bounds check. Thi...
CVE-2018-9502In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out-of-bounds read due to a missing bounds check. Thi...
CVE-2018-9501In the SetupWizard, there is a possible Factory Reset Protection bypass due to a permissions bypass. This could lead to ...
CVE-2018-9499In readVector of iCrypto.cpp, there is a possible invalid read due to uninitialized data. This could lead to local infor...
CVE-2018-9498In SkSampler::Fill of SkSampler.cpp, there is a possible out of bounds write due to an integer overflow. This could lead...
CVE-2018-9497In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv_av8 of impeg2_format_conv.s there is a possible out of bounds write due to mis...
CVE-2018-9496In ixheaacd_real_synth_fft_p3 of ixheaacd_esbr_fft.c there is a possible out of bounds write due to a missing bounds che...
CVE-2018-9493In the content provider of the download manager, there is a possible SQL injection due to improper input validation. Thi...
CVE-2018-9492In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead...
CVE-2018-9491In AMediaCodecCryptoInfo_new of NdkMediaCodec.cpp, there is a possible out-of-bounds write due to an integer overflow. T...
CVE-2018-9490In CollectValuesOrEntriesImpl of elements.cc, there is possible remote code execution due to type confusion. This could ...
CVE-2018-9476In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible use-after-free due to improper locking. This could lea...
CVE-2018-9473In ihevcd_parse_sei_payload of ihevcd_parse_headers.c, there is a possible out-of-bounds write due to an integer overflo...
CVE-2018-9452In getOffsetForHorizontal of Layout.java, there is a possible application hang due to a slow width calculation. This cou...
CVE-2018-11750Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As...
CVE-2018-11748Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world ...
CVE-2018-17886An issue was discovered in JEESNS 1.3. The XSS filter in com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java ...
CVE-2018-17884XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via th...
CVE-2018-17787On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the PO...
CVE-2018-17786On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not...
CVE-2018-17596In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ...
CVE-2018-17595In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /ba...
CVE-2018-17594AirTies Air 5443v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
CVE-2018-17593AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now