2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12910 | — | — | 4.2% | Jul 5, 2018 | The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty... |
| CVE-2018-12691 | — | — | 0.7% | Jul 5, 2018 | Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS... |
| CVE-2018-12021 | — | — | 1.6% | Jul 5, 2018 | Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. Wh... |
| CVE-2018-13305 | — | — | 1.4% | Jul 5, 2018 | In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function ... |
| CVE-2018-13304 | — | — | 1.1% | Jul 5, 2018 | In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_prof... |
| CVE-2018-13303 | — | — | 1.4% | Jul 5, 2018 | In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in the avpriv_ac3_parse_header function in li... |
| CVE-2018-13302 | — | — | 2.2% | Jul 5, 2018 | In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have multiple independen... |
| CVE-2018-13301 | — | — | 1.4% | Jul 5, 2018 | In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header functio... |
| CVE-2018-13300 | — | — | 2.3% | Jul 5, 2018 | In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the ha... |
| CVE-2018-13252 | — | — | 0.7% | Jul 5, 2018 | Entrust Datacard Syntera CS 5.x has XSS via the name field of "Domain or Computer Name" in the login page. |
| CVE-2018-3768 | — | — | — | Jul 5, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1000539. Reason: This candidate is a reservati... |
| CVE-2018-3767 | — | — | 1.5% | Jul 5, 2018 | `memjs` versions <= 1.1.0 allocates and stores buffers on typed input, resulting in DoS and uninitialized memory usage. |
| CVE-2018-8026 | — | — | 9.0% | Jul 5, 2018 | This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in... |
| CVE-2018-13251 | — | — | 1.5% | Jul 5, 2018 | In libming 0.4.8, there is an excessive memory allocation attempt in the readBytes function of the util/read.c file, rel... |
| CVE-2018-13250 | — | — | 1.5% | Jul 5, 2018 | libming 0.4.8 has a NULL pointer dereference in the getString function of the decompile.c file, related to decompileSTRI... |
| CVE-2018-9185 | — | — | 2.1% | Jul 5, 2018 | An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login cre... |
| CVE-2018-8038 | — | — | 10.7% | Jul 5, 2018 | Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing t... |
| CVE-2018-13233 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for GSI, an Ethereum token, has an integer overflow in which "amoun... |
| CVE-2018-13232 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterCoin), an Ethereum token, has... |
| CVE-2018-13231 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterToken), an Ethereum token, ha... |
| CVE-2018-13230 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for DestiNeed (DSN), an Ethereum token, has an integer overflow in ... |
| CVE-2018-13229 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for RiptideCoin (RIPT), an Ethereum token, has an integer overflow ... |
| CVE-2018-13228 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for Crowdnext (CNX), an Ethereum token, has an integer overflow in ... |
| CVE-2018-13227 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for MoneyChainNet (MCN), an Ethereum token, has an integer overflow... |
| CVE-2018-13226 | — | — | 1.0% | Jul 5, 2018 | The sell function of a smart contract implementation for YLCToken, an Ethereum token, has an integer overflow in which "... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now