2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5170 | — | — | 1.8% | Jun 11, 2018 | It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a use... |
| CVE-2018-5169 | — | — | 1.4% | Jun 11, 2018 | If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home p... |
| CVE-2018-5168 | — | — | 2.4% | Jun 11, 2018 | Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of ... |
| CVE-2018-5167 | — | — | 1.4% | Jun 11, 2018 | The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" ... |
| CVE-2018-5166 | — | — | 2.4% | Jun 11, 2018 | WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirec... |
| CVE-2018-5164 | — | — | 1.6% | Jun 11, 2018 | Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixe... |
| CVE-2018-5163 | — | — | 2.1% | Jun 11, 2018 | If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to ... |
| CVE-2018-5162 | — | — | 2.0% | Jun 11, 2018 | Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects ... |
| CVE-2018-5161 | — | — | 2.1% | Jun 11, 2018 | Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thu... |
| CVE-2018-5160 | — | — | 2.7% | Jun 11, 2018 | WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. Thi... |
| CVE-2018-5159 | — | — | 21.3% | Jun 11, 2018 | An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks,... |
| CVE-2018-5158 | — | — | 10.6% | Jun 11, 2018 | The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injec... |
| CVE-2018-5157 | — | — | 1.6% | Jun 11, 2018 | Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for th... |
| CVE-2018-5155 | — | — | 3.5% | Jun 11, 2018 | A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a... |
| CVE-2018-5154 | — | — | 3.3% | Jun 11, 2018 | A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This result... |
| CVE-2018-5153 | — | — | 1.7% | Jun 11, 2018 | If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can res... |
| CVE-2018-5152 | — | — | 1.7% | Jun 11, 2018 | WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com ... |
| CVE-2018-5151 | — | — | 2.8% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume t... |
| CVE-2018-5150 | — | — | 3.2% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed eviden... |
| CVE-2018-5148 | — | — | 3.0% | Jun 11, 2018 | A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used... |
| CVE-2018-5147 | — | — | 2.5% | Jun 11, 2018 | The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Andro... |
| CVE-2018-5146 | — | — | 12.1% | Jun 11, 2018 | An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerab... |
| CVE-2018-5145 | — | — | 3.0% | Jun 11, 2018 | Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume tha... |
| CVE-2018-5144 | — | — | 3.3% | Jun 11, 2018 | An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parame... |
| CVE-2018-5143 | — | — | 0.9% | Jun 11, 2018 | URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scri... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now