2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5813 | MEDIUM | 6.5 | 2.1% | Dec 7, 2018 | An error within the "parse_minolta()" function (dcraw/dcraw.c) in LibRaw versions prior to 0.18.11 can be exploited to t... |
| CVE-2018-5800 | MEDIUM | 6.5 | 2.5% | Dec 7, 2018 | An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions ... |
| CVE-2018-1896 | MEDIUM | 4.6 | 1.0% | Dec 7, 2018 | IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to ... |
| CVE-2018-1883 | MEDIUM | 5.3 | 2.4% | Dec 7, 2018 | A problem within the IBM MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, and 9.1.0.0 Console REST API Could allow attackers to execute a ... |
| CVE-2018-1663 | MEDIUM | 5.9 | 2.3% | Dec 7, 2018 | IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information,... |
| CVE-2018-19665 | MEDIUM | 5.7 | 0.9% | Dec 6, 2018 | The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption. |
| CVE-2018-9566 | MEDIUM | 5.7 | 0.4% | Dec 6, 2018 | In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a missing bounds check. ... |
| CVE-2018-9552 | MEDIUM | 5.5 | 0.5% | Dec 6, 2018 | In ihevcd_sao_shift_ctb of ihevcd_sao.c there is a possible out of bounds write due to missing bounds check. This could ... |
| CVE-2018-9548 | MEDIUM | 5.5 | 0.2% | Dec 6, 2018 | In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missing URI validation. Th... |
| CVE-2018-1935 | MEDIUM | 4.3 | 1.3% | Dec 6, 2018 | IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request... |
| CVE-2018-1871 | MEDIUM | 5.4 | 1.0% | Dec 6, 2018 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross... |
| CVE-2018-1525 | MEDIUM | 5.9 | 1.1% | Dec 6, 2018 | IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the fa... |
| CVE-2018-1505 | MEDIUM | 4 | 0.4% | Dec 6, 2018 | IBM i2 Enterprise Insight Analysis 2.1.7 allows web pages to be stored locally which can be read by another user on the ... |
| CVE-2018-1504 | MEDIUM | 6.1 | 1.1% | Dec 6, 2018 | IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By p... |
| CVE-2018-19886 | MEDIUM | 5.5 | 1.0% | Dec 6, 2018 | An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud... |
| CVE-2018-1002101 | MEDIUM | 5.9 | 4.1% | Dec 5, 2018 | In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up... |
| CVE-2018-1732 | MEDIUM | 5.3 | 1.4% | Dec 5, 2018 | IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used... |
| CVE-2018-1728 | MEDIUM | 5.4 | 0.7% | Dec 5, 2018 | IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2018-1697 | MEDIUM | 4.3 | 1.2% | Dec 5, 2018 | IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a specially crafted HTTP ... |
| CVE-2018-1650 | MEDIUM | 5.9 | 0.3% | Dec 5, 2018 | IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication confi... |
| CVE-2018-1568 | MEDIUM | 4 | 0.4% | Dec 5, 2018 | IBM QRadar SIEM 7.2 and 7.3 allows web pages to be stored locally which can be read by another user on the system. IBM X... |
| CVE-2018-6982 | MEDIUM | 6.5 | 0.5% | Dec 4, 2018 | VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stac... |
| CVE-2018-19841 | MEDIUM | 5.5 | 2.5% | Dec 4, 2018 | The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause... |
| CVE-2018-1840 | MEDIUM | 6 | 2.1% | Dec 3, 2018 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, ca... |
| CVE-2018-6332 | MEDIUM | 5.9 | 1.1% | Dec 3, 2018 | A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spe... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now