2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9568 | HIGH | 7.8 | 0.7% | Dec 6, 2018 | In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escala... |
| CVE-2018-9565 | HIGH | 7.5 | 1.1% | Dec 6, 2018 | In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to rem... |
| CVE-2018-9562 | HIGH | 7.5 | 1.1% | Dec 6, 2018 | In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parameter size. This could... |
| CVE-2018-9560 | HIGH | 7.8 | 0.2% | Dec 6, 2018 | In HID_DevAddRecord of hidd_api.cc, there is a possible out-of-bounds write due to a missing bounds check. This could le... |
| CVE-2018-9558 | HIGH | 7.8 | 0.2% | Dec 6, 2018 | In rw_t2t_handle_tlv_detect of rw_t2t_ndef.cc, there is a possible out-of-bounds write due to a missing bounds check. Th... |
| CVE-2018-9555 | HIGH | 8.8 | 0.7% | Dec 6, 2018 | In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lea... |
| CVE-2018-9553 | HIGH | 7.8 | 1.1% | Dec 6, 2018 | In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure default value. This could... |
| CVE-2018-9551 | HIGH | 7.8 | 1.1% | Dec 6, 2018 | In CAacDecoder_Init of aacdecoder.cpp, there is a possible out-of-bound write due to a missing bounds check. This could ... |
| CVE-2018-9550 | HIGH | 7.8 | 1.2% | Dec 6, 2018 | In CAacDecoder_Init of aacdecoder.cpp, there is a possible out of bounds write due to a missing bounds check. This could... |
| CVE-2018-9549 | HIGH | 7.8 | 1.1% | Dec 6, 2018 | In lppTransposer of lpp_tran.cpp there is a possible out of bounds write due to missing bounds check. This could lead to... |
| CVE-2018-9547 | HIGH | 7.8 | 0.2% | Dec 6, 2018 | In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to... |
| CVE-2018-9538 | HIGH | 7.8 | 0.2% | Dec 6, 2018 | In V4L2SliceVideoDecodeAccelerator::Dequeue of v4l2_slice_video_decode_accelerator.cc, there is a possible out of bounds... |
| CVE-2018-1002103 | HIGH | 8.1 | 0.7% | Dec 5, 2018 | In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM... |
| CVE-2018-15797 | HIGH | 8.4 | 1.6% | Dec 5, 2018 | Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin us... |
| CVE-2018-1941 | HIGH | 8.4 | 0.3% | Dec 5, 2018 | IBM Campaign 9.1.0 and 9.1.2 could allow a local user to obtain admini privileges due to the application not validating ... |
| CVE-2018-1730 | HIGH | 7.1 | 1.9% | Dec 5, 2018 | IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A re... |
| CVE-2018-18993 | HIGH | 7.8 | 1.8% | Dec 4, 2018 | Two stack-based buffer overflow vulnerabilities have been discovered in CX-One Versions 4.42 and prior (CX-Programmer Ve... |
| CVE-2018-19591 | HIGH | 7.5 | 5.5% | Dec 4, 2018 | In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads... |
| CVE-2018-6981 | HIGH | 8.8 | 1.3% | Dec 4, 2018 | VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without E... |
| CVE-2018-4021 | HIGH | 7.2 | 72.2% | Dec 3, 2018 | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the paramete... |
| CVE-2018-4020 | HIGH | 7.2 | 48.7% | Dec 3, 2018 | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the paramete... |
| CVE-2018-4019 | HIGH | 7.2 | 48.7% | Dec 3, 2018 | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the paramete... |
| CVE-2018-3854 | HIGH | 7.1 | 0.4% | Dec 3, 2018 | An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 20... |
| CVE-2018-6439 | HIGH | 7.8 | 0.3% | Dec 3, 2018 | A Vulnerability in the configdownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8... |
| CVE-2018-16863 | HIGH | 7.3 | 1.2% | Dec 3, 2018 | It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now