2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-16745An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized...
CVE-2018-16744An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized...
CVE-2018-16743An issue was discovered in mgetty before 1.2.1. In contrib/next-login/login.c, the command-line parameter username is pa...
CVE-2018-16742An issue was discovered in mgetty before 1.2.1. In contrib/scrts.c, a stack-based buffer overflow can be triggered via a...
CVE-2018-16741An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanit...
CVE-2018-16987Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstra...
CVE-2018-5549On BIG-IP APM 11.6.0-11.6.3.1, 12.1.0-12.1.3.3, 13.0.0, and 13.1.0-13.1.0.3, APMD may core when processing SAML Assertio...
CVE-2018-5548On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of AP...
CVE-2018-5545On F5 WebSafe Alert Server 1.0.0-4.2.6, a malicious, authenticated user can execute code on the alert server by using a ...
CVE-2018-16985In Lizard (formerly LZ5) 2.0, use of an invalid memory address was discovered in LZ5_compress_continue in lz5_compress.c...
CVE-2018-15310A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP softwar...
CVE-2018-16983NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocki...
CVE-2018-16982Open Chinese Convert (OpenCC) 1.0.5 allows attackers to cause a denial of service (segmentation fault) because BinaryDic...
CVE-2018-8479A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on W...
CVE-2018-8475A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "W...
CVE-2018-8474A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messa...
CVE-2018-8470A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a univers...
CVE-2018-8469An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont...
CVE-2018-8468An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privil...
CVE-2018-8467A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8466A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8465A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2018-8464An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "...
CVE-2018-8463An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont...
CVE-2018-8462An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now