2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16745 | — | — | 0.4% | Sep 13, 2018 | An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized... |
| CVE-2018-16744 | — | — | 1.0% | Sep 13, 2018 | An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized... |
| CVE-2018-16743 | — | — | 0.4% | Sep 13, 2018 | An issue was discovered in mgetty before 1.2.1. In contrib/next-login/login.c, the command-line parameter username is pa... |
| CVE-2018-16742 | — | — | 0.4% | Sep 13, 2018 | An issue was discovered in mgetty before 1.2.1. In contrib/scrts.c, a stack-based buffer overflow can be triggered via a... |
| CVE-2018-16741 | — | — | 1.3% | Sep 13, 2018 | An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanit... |
| CVE-2018-16987 | — | — | 1.3% | Sep 13, 2018 | Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstra... |
| CVE-2018-5549 | — | — | 1.8% | Sep 13, 2018 | On BIG-IP APM 11.6.0-11.6.3.1, 12.1.0-12.1.3.3, 13.0.0, and 13.1.0-13.1.0.3, APMD may core when processing SAML Assertio... |
| CVE-2018-5548 | — | — | 1.4% | Sep 13, 2018 | On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of AP... |
| CVE-2018-5545 | — | — | 2.4% | Sep 13, 2018 | On F5 WebSafe Alert Server 1.0.0-4.2.6, a malicious, authenticated user can execute code on the alert server by using a ... |
| CVE-2018-16985 | — | — | 1.5% | Sep 13, 2018 | In Lizard (formerly LZ5) 2.0, use of an invalid memory address was discovered in LZ5_compress_continue in lz5_compress.c... |
| CVE-2018-15310 | — | — | 0.9% | Sep 13, 2018 | A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP softwar... |
| CVE-2018-16983 | — | — | 3.1% | Sep 13, 2018 | NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocki... |
| CVE-2018-16982 | — | — | 1.0% | Sep 13, 2018 | Open Chinese Convert (OpenCC) 1.0.5 allows attackers to cause a denial of service (segmentation fault) because BinaryDic... |
| CVE-2018-8479 | — | — | 2.1% | Sep 13, 2018 | A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on W... |
| CVE-2018-8475 | — | — | 14.6% | Sep 13, 2018 | A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "W... |
| CVE-2018-8474 | — | — | 38.2% | Sep 13, 2018 | A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messa... |
| CVE-2018-8470 | — | — | 3.3% | Sep 13, 2018 | A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a univers... |
| CVE-2018-8469 | — | — | 15.4% | Sep 13, 2018 | An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont... |
| CVE-2018-8468 | — | — | 11.8% | Sep 13, 2018 | An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privil... |
| CVE-2018-8467 | — | — | 69.0% | Sep 13, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8466 | — | — | 69.0% | Sep 13, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8465 | — | — | 14.6% | Sep 13, 2018 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2018-8464 | — | — | 42.6% | Sep 13, 2018 | An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "... |
| CVE-2018-8463 | — | — | 15.4% | Sep 13, 2018 | An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont... |
| CVE-2018-8462 | — | — | 1.2% | Sep 13, 2018 | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now