2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12265 | — | — | 2.9% | Jun 13, 2018 | Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2... |
| CVE-2018-12264 | — | — | 2.9% | Jun 13, 2018 | Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::Val... |
| CVE-2018-12263 | — | — | 1.1% | Jun 13, 2018 | portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI. |
| CVE-2018-5851 | — | — | 0.2% | Jun 12, 2018 | Buffer over flow can occur while processing a HTT_T2H_MSG_TYPE_TX_COMPL_IND message with an out-of-range num_msdus value... |
| CVE-2018-5849 | — | — | 0.1% | Jun 12, 2018 | Due to a race condition in the QTEECOM driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD... |
| CVE-2018-5848 | — | — | 0.4% | Jun 12, 2018 | In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result... |
| CVE-2018-5847 | — | — | 0.2% | Jun 12, 2018 | Early or late retirement of rotation requests can result in a Use After Free condition in all Android releases from CAF ... |
| CVE-2018-5844 | — | — | 0.2% | Jun 12, 2018 | In the video driver function set_output_buffers(), binfo can be accessed after being freed in a failure scenario in all ... |
| CVE-2018-5843 | — | — | 0.2% | Jun 12, 2018 | In the function wma_pdev_div_info_evt_handler() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, Q... |
| CVE-2018-5842 | — | — | 0.2% | Jun 12, 2018 | An arbitrary address write can occur if a compromised WLAN firmware sends incorrect data to WLAN driver in all Android r... |
| CVE-2018-3582 | — | — | 0.2% | Jun 12, 2018 | Buffer overflow can occur due to improper input validation in multiple WMA event handler functions in all Android releas... |
| CVE-2018-3581 | — | — | 0.2% | Jun 12, 2018 | In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux K... |
| CVE-2018-3579 | — | — | 0.2% | Jun 12, 2018 | In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux K... |
| CVE-2018-3576 | — | — | 0.2% | Jun 12, 2018 | improper validation of array index in WiFi driver function sapInterferenceRssiCount() leads to array out-of-bounds acces... |
| CVE-2018-3572 | — | — | 0.2% | Jun 12, 2018 | While processing a DSP buffer in an audio driver's event handler, an index of a buffer is not checked before accessing t... |
| CVE-2018-3571 | — | — | 0.2% | Jun 12, 2018 | In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux K... |
| CVE-2018-0496 | — | — | 2.4% | Jun 12, 2018 | Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / Proton... |
| CVE-2018-12261 | — | — | 0.3% | Jun 12, 2018 | An issue was discovered on Momentum Axel 720P 5.1.8 devices. All processes run as root. |
| CVE-2018-12260 | — | — | 0.4% | Jun 12, 2018 | An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing t... |
| CVE-2018-12259 | — | — | 0.4% | Jun 12, 2018 | An issue was discovered on Momentum Axel 720P 5.1.8 devices. Root access can be obtained via UART pins without any restr... |
| CVE-2018-12258 | — | — | 0.5% | Jun 12, 2018 | An issue was discovered on Momentum Axel 720P 5.1.8 devices. Custom Firmware Upgrade is possible via an SD Card. With ph... |
| CVE-2018-12257 | — | — | 0.4% | Jun 12, 2018 | An issue was discovered on Momentum Axel 720P 5.1.8 devices. There is Authenticated Custom Firmware Upgrade via DNS Hija... |
| CVE-2018-12254 | — | — | 2.6% | Jun 12, 2018 | router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to ... |
| CVE-2018-1151 | — | — | 8.4% | Jun 12, 2018 | The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers... |
| CVE-2018-10509 | — | — | 1.1% | Jun 12, 2018 | A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to exploit it via a Browser Refresh att... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now