2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-12123MEDIUM4.3Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascrip...
CVE-2018-12122HIGH7.5Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker...
CVE-2018-12121HIGH7.5Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By...
CVE-2018-12120HIGH8.1Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger...
CVE-2018-12116HIGH7.5Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use uns...
CVE-2018-17156In FreeBSD before 11.2-STABLE(r340268) and 11.2-RELEASE-p5, due to incorrectly accounting for padding on 64-bit platform...
CVE-2018-1584MEDIUM5.4IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2018-14749Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6...
CVE-2018-14748Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QT...
CVE-2018-14747NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, ...
CVE-2018-14746Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2...
CVE-2018-5918Possible buffer overflow in DRM Trusted application due to lack of check function return values in Snapdragon Automobile...
CVE-2018-5917Possible buffer overflow in OEM crypto function due to improper input validation in Snapdragon Automobile, Snapdragon Mo...
CVE-2018-5916Buffer overread while decoding PDP modify request or network initiated secondary PDP activation in Snapdragon Automobile...
CVE-2018-5912Potential buffer overflow in Video due to lack of input validation in input and output values in Snapdragon Automobile, ...
CVE-2018-5877In the device programmer target-side code for firehose, a string may not be properly NULL terminated can lead to a incor...
CVE-2018-5870While loading a service image, an untrusted pointer dereference can occur in Snapdragon Mobile in versions SD 835, SDA66...
CVE-2018-11996When a malformed command is sent to the device programmer, an out-of-bounds access can occur in Snapdragon Automobile, S...
CVE-2018-11994SMMU secure camera logic allows secure camera controllers to access HLOS memory during session in Snapdragon Automobile,...
CVE-2018-11921Failure condition is not handled properly and the correct error code is not returned. It could cause unintended SUI beha...
CVE-2018-11264Possible buffer overflow in Ontario fingerprint code due to lack of input validation for the parameters coming into TZ f...
CVE-2018-16857HIGH7.4Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict...
CVE-2018-16853HIGH7.5Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is buil...
CVE-2018-16852MEDIUM6.5Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of...
CVE-2018-16851MEDIUM6.5Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the proce...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now