2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-5170It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a use...
CVE-2018-5169If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home p...
CVE-2018-5168Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of ...
CVE-2018-5167The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" ...
CVE-2018-5166WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirec...
CVE-2018-5164Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixe...
CVE-2018-5163If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to ...
CVE-2018-5162Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects ...
CVE-2018-5161Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thu...
CVE-2018-5160WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. Thi...
CVE-2018-5159An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks,...
CVE-2018-5158The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injec...
CVE-2018-5157Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for th...
CVE-2018-5155A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a...
CVE-2018-5154A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This result...
CVE-2018-5153If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can res...
CVE-2018-5152WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com ...
CVE-2018-5151Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume t...
CVE-2018-5150Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed eviden...
CVE-2018-5148A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used...
CVE-2018-5147The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Andro...
CVE-2018-5146An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerab...
CVE-2018-5145Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume tha...
CVE-2018-5144An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parame...
CVE-2018-5143URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scri...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now