2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20548 | HIGH | 8.8 | 1.8% | Dec 28, 2018 | There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 1bpp data. |
| CVE-2018-20547 | HIGH | 8.1 | 1.8% | Dec 28, 2018 | There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp dat... |
| CVE-2018-20546 | HIGH | 8.1 | 2.3% | Dec 28, 2018 | There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the defau... |
| CVE-2018-20545 | HIGH | 8.8 | 2.4% | Dec 28, 2018 | There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data. |
| CVE-2018-20437 | HIGH | 7.5 | 2.4% | Dec 25, 2018 | An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05. An a... |
| CVE-2018-20247 | HIGH | 7.8 | 54.5% | Dec 24, 2018 | In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a ... |
| CVE-2018-7801 | HIGH | 8.8 | 6.3% | Dec 24, 2018 | A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable access with maximu... |
| CVE-2018-8920 | HIGH | 7.2 | 1.0% | Dec 24, 2018 | Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266... |
| CVE-2018-8919 | HIGH | 8.3 | 1.4% | Dec 24, 2018 | Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-1... |
| CVE-2018-15465 | HIGH | 8.1 | 2.4% | Dec 24, 2018 | A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authen... |
| CVE-2018-19322 | HIGH | 7.8 | 1.9% | Dec 21, 2018 | The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X... |
| CVE-2018-19321 | HIGH | 7.8 | 3.7% | Dec 21, 2018 | The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X... |
| CVE-2018-19320 | HIGH | 7.8 | 3.6% | Dec 21, 2018 | The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ... |
| CVE-2018-5196 | HIGH | 8.8 | 1.4% | Dec 21, 2018 | Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. By persuading a victim... |
| CVE-2018-20191 | HIGH | 7.5 | 3.7% | Dec 20, 2018 | hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which ... |
| CVE-2018-20216 | HIGH | 7.5 | 3.9% | Dec 20, 2018 | QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishand... |
| CVE-2018-20125 | HIGH | 7.5 | 3.7% | Dec 20, 2018 | hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive me... |
| CVE-2018-1000878 | HIGH | 8.8 | 4.4% | Dec 20, 2018 | libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: ... |
| CVE-2018-1000877 | HIGH | 8.8 | 4.6% | Dec 20, 2018 | libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: ... |
| CVE-2018-1000876 | HIGH | 7.8 | 0.7% | Dec 20, 2018 | binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_boun... |
| CVE-2018-1000857 | HIGH | 8.8 | 3.3% | Dec 20, 2018 | log-user-session version 0.7 and earlier contains a Directory Traversal vulnerability in Main SUID-binary /usr/local/bin... |
| CVE-2018-5200 | HIGH | 7.8 | 1.7% | Dec 20, 2018 | KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV ... |
| CVE-2018-5199 | HIGH | 8.8 | 1.7% | Dec 20, 2018 | In Veraport G3 ALL on MacOS, due to insufficient domain validation, It is possible to overwrite installation file to mal... |
| CVE-2018-5198 | HIGH | 8.1 | 1.4% | Dec 20, 2018 | In Veraport G3 ALL on MacOS, a race condition when calling the Veraport API allow remote attacker to cause arbitrary fil... |
| CVE-2018-1973 | HIGH | 7.2 | 2.3% | Dec 20, 2018 | IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves fu... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now