2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-3948HIGH7.5An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP se...
CVE-2018-15768Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due...
CVE-2018-15767The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerab...
CVE-2018-1928MEDIUM6.7IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileg...
CVE-2018-1927MEDIUM6.5IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...
CVE-2018-1897HIGH8.4IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack based buffer overflow, ...
CVE-2018-9072In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient i...
CVE-2018-16097LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated...
CVE-2018-16093In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient s...
CVE-2018-0716Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central...
CVE-2018-14637MEDIUM6.1The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertion...
CVE-2018-19777In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrate...
CVE-2018-19764Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-19763There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2 that will cause a den...
CVE-2018-19762There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a...
CVE-2018-19761There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a ...
CVE-2018-19760cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak.
CVE-2018-19759There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that wil...
CVE-2018-19758There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of ser...
CVE-2018-19757There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that wi...
CVE-2018-19756There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a den...
CVE-2018-19755There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will...
CVE-2018-19527i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings.
CVE-2018-19497MEDIUM6.5In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is...
CVE-2018-1000819Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-19131. Reason: This candidate is a reservation...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now