2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12123 | MEDIUM | 4.3 | 4.0% | Nov 28, 2018 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascrip... |
| CVE-2018-12122 | HIGH | 7.5 | 41.3% | Nov 28, 2018 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker... |
| CVE-2018-12121 | HIGH | 7.5 | 10.2% | Nov 28, 2018 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By... |
| CVE-2018-12120 | HIGH | 8.1 | 4.3% | Nov 28, 2018 | Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger... |
| CVE-2018-12116 | HIGH | 7.5 | 4.6% | Nov 28, 2018 | Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use uns... |
| CVE-2018-17156 | — | — | 1.6% | Nov 28, 2018 | In FreeBSD before 11.2-STABLE(r340268) and 11.2-RELEASE-p5, due to incorrectly accounting for padding on 64-bit platform... |
| CVE-2018-1584 | MEDIUM | 5.4 | 1.0% | Nov 28, 2018 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2018-14749 | — | — | 1.2% | Nov 28, 2018 | Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6... |
| CVE-2018-14748 | — | — | 1.3% | Nov 28, 2018 | Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QT... |
| CVE-2018-14747 | — | — | 1.3% | Nov 28, 2018 | NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, ... |
| CVE-2018-14746 | — | — | 3.3% | Nov 28, 2018 | Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2... |
| CVE-2018-5918 | — | — | 0.2% | Nov 28, 2018 | Possible buffer overflow in DRM Trusted application due to lack of check function return values in Snapdragon Automobile... |
| CVE-2018-5917 | — | — | 0.3% | Nov 28, 2018 | Possible buffer overflow in OEM crypto function due to improper input validation in Snapdragon Automobile, Snapdragon Mo... |
| CVE-2018-5916 | — | — | 0.4% | Nov 28, 2018 | Buffer overread while decoding PDP modify request or network initiated secondary PDP activation in Snapdragon Automobile... |
| CVE-2018-5912 | — | — | 0.2% | Nov 28, 2018 | Potential buffer overflow in Video due to lack of input validation in input and output values in Snapdragon Automobile, ... |
| CVE-2018-5877 | — | — | 0.2% | Nov 28, 2018 | In the device programmer target-side code for firehose, a string may not be properly NULL terminated can lead to a incor... |
| CVE-2018-5870 | — | — | 0.2% | Nov 28, 2018 | While loading a service image, an untrusted pointer dereference can occur in Snapdragon Mobile in versions SD 835, SDA66... |
| CVE-2018-11996 | — | — | 0.2% | Nov 28, 2018 | When a malformed command is sent to the device programmer, an out-of-bounds access can occur in Snapdragon Automobile, S... |
| CVE-2018-11994 | — | — | 0.2% | Nov 28, 2018 | SMMU secure camera logic allows secure camera controllers to access HLOS memory during session in Snapdragon Automobile,... |
| CVE-2018-11921 | — | — | 0.2% | Nov 28, 2018 | Failure condition is not handled properly and the correct error code is not returned. It could cause unintended SUI beha... |
| CVE-2018-11264 | — | — | 0.2% | Nov 28, 2018 | Possible buffer overflow in Ontario fingerprint code due to lack of input validation for the parameters coming into TZ f... |
| CVE-2018-16857 | HIGH | 7.4 | 2.3% | Nov 28, 2018 | Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict... |
| CVE-2018-16853 | HIGH | 7.5 | 3.1% | Nov 28, 2018 | Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is buil... |
| CVE-2018-16852 | MEDIUM | 6.5 | 2.2% | Nov 28, 2018 | Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of... |
| CVE-2018-16851 | MEDIUM | 6.5 | 3.3% | Nov 28, 2018 | Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the proce... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now