2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-5142If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission not...
CVE-2018-5141A vulnerability in the notifications Push API where notifications can be sent through service workers by web content wit...
CVE-2018-5140Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise p...
CVE-2018-5138A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Cust...
CVE-2018-5137A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. Thi...
CVE-2018-5136A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing th...
CVE-2018-5135WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject script...
CVE-2018-5134WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache",...
CVE-2018-5133If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this...
CVE-2018-5132The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a...
CVE-2018-5131Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-s...
CVE-2018-5130When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially expl...
CVE-2018-5129A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages...
CVE-2018-5128A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operatio...
CVE-2018-5127A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentiall...
CVE-2018-5126Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corruption and we presume t...
CVE-2018-5125Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corrup...
CVE-2018-5122A potential integer overflow in the "DoCrypt" function of WebCrypto was identified. If a means was found of exploiting i...
CVE-2018-5121Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When use...
CVE-2018-5119The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin cont...
CVE-2018-5118The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta ...
CVE-2018-5117If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to sc...
CVE-2018-5116WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames ...
CVE-2018-5115If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed ...
CVE-2018-5114If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible throug...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now