2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11950Unapproved TrustZone applications can be loaded and executed in Snapdragon Mobile in version SD 845, SD 850
CVE-2018-11854Lack of check of valid length of input parameter may cause buffer overwrite in WLAN in Snapdragon Mobile in version SD 8...
CVE-2018-11853Lack of check on out of range for channels When processing channel list set command will lead to buffer flow in Snapdrag...
CVE-2018-11850Lack of check on remaining length parameter When processing scan start command will lead to buffer flow in Snapdragon Au...
CVE-2018-11849Lack of check on out of range of bssid parameter When processing scan start command will lead to buffer flow in Snapdrag...
CVE-2018-11846The use of a non-time-constant memory comparison operation can lead to timing/side channel attacks in Snapdragon Mobile ...
CVE-2018-11828When FW tries to get random mac address generated from new SW RNG and ADC values read are constant then DUT get struck i...
CVE-2018-11824A stack-based buffer overflow can occur in a firmware routine in Snapdragon Mobile, Snapdragon Wear in version MDM9206, ...
CVE-2018-11822A possible integer overflow may happen in WLAN during memory allocation in Snapdragon Mobile in version SD 835, SD 845, ...
CVE-2018-11821Possible integer overflow may happen in WLAN during memory allocation in Snapdragon Mobile, Snapdragon Wear in version I...
CVE-2018-11305When a series of FDAL messages are sent to the modem, a Use After Free condition can occur in Snapdragon Automobile, Sna...
CVE-2018-18656The PureVPN client before 6.1.0 for Windows stores Login Credentials (username and password) in cleartext. The location ...
CVE-2018-18655Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email b...
CVE-2018-18654Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a wo...
CVE-2018-18653The Linux kernel, as used in Ubuntu 18.10 and when booted with UEFI Secure Boot enabled, allows privileged local users t...
CVE-2018-18652A remote command execution vulnerability in Veritas NetBackup Appliance before 3.1.2 allows authenticated administrators...
CVE-2018-17904Reliance 4 SCADA/HMI, Version 4.7.3 Update 3 and prior. This vulnerability could allow an unauthorized attacker to injec...
CVE-2018-14665A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh...
CVE-2018-3971HIGH7.8An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Aler...
CVE-2018-3970MEDIUM5.5An exploitable memory disclosure vulnerability exists in the 0x222000 IOCTL handler functionality of Sophos HitmanPro.Al...
CVE-2018-18651An issue was discovered in Xpdf 4.00. catalog->getNumPages() in AcroForm.cc allows attackers to launch a denial of servi...
CVE-2018-18650An issue was discovered in Xpdf 4.00. XRef::readXRefStream in XRef.cc allows attackers to launch a denial of service (In...
CVE-2018-8955The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installatio...
CVE-2018-18638A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execu...
CVE-2018-18621CommuniGate Pro 6.2 allows stored XSS via a message body in Pronto! Mail Composer, which is mishandled in /MIME/INBOX-MM...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now