2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-20482MEDIUM4.7GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to c...
CVE-2018-20467MEDIUM6.5In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and...
CVE-2018-20459MEDIUM5.5In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-...
CVE-2018-20458MEDIUM5.5In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a d...
CVE-2018-20457MEDIUM5.5In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-ser...
CVE-2018-20451MEDIUM6.5The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attacke...
CVE-2018-8917MEDIUM6.5Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows rem...
CVE-2018-8918MEDIUM6.5Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote at...
CVE-2018-20360MEDIUM5.5An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freewar...
CVE-2018-20124MEDIUM5.5hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with...
CVE-2018-20126MEDIUM5.5hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.
CVE-2018-1000880MEDIUM6.5libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: I...
CVE-2018-1000879MEDIUM6.5libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: ...
CVE-2018-1000874MEDIUM6.1PHP cebe markdown parser version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in all distribute...
CVE-2018-1000873MEDIUM6.5Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Jav...
CVE-2018-1000855MEDIUM6.1easymon version 1.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Endpoint where monitoring is moun...
CVE-2018-1000852MEDIUM6.5FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unkno...
CVE-2018-1000842MEDIUM6.1FatFreeCRM version <=0.14.1, >=0.15.0 <=0.15.1, >=0.16.0 <=0.16.3, >=0.17.0 <=0.17.2, ==0.18.0 contains a Cross Site Scr...
CVE-2018-1000814MEDIUM6.5aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and ...
CVE-2018-7365MEDIUM5.1All versions up to ZXCLOUD iRAI V5.01.05 of the ZTE uSmartView product are impacted by untrusted search path vulnerabili...
CVE-2018-1677MEDIUM5.1IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of serv...
CVE-2018-1661MEDIUM6.5IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attac...
CVE-2018-6669MEDIUM6.3A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or loca...
CVE-2018-20307MEDIUM4.3Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain ...
CVE-2018-19522MEDIUM5.5DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x800020F4) with a buffe...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now