2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-5113The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but thi...
CVE-2018-5112Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension ma...
CVE-2018-5111When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoo...
CVE-2018-5110If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rend...
CVE-2018-5109An audio capture session can started under an incorrect origin from the site making the capture request. Users are still...
CVE-2018-5108A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data...
CVE-2018-5107The printing process can bypass local access protections to read files available through symlinks, bypassing local file ...
CVE-2018-5106Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a ...
CVE-2018-5105WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an ...
CVE-2018-5104A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, res...
CVE-2018-5103A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This resul...
CVE-2018-5102A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potent...
CVE-2018-5101A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potent...
CVE-2018-5100A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while...
CVE-2018-5099A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that h...
CVE-2018-5098A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script conte...
CVE-2018-5097A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is m...
CVE-2018-5096A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exp...
CVE-2018-5095An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at l...
CVE-2018-5094A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called followed by garbage collec...
CVE-2018-5093A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially e...
CVE-2018-5092A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of fr...
CVE-2018-5091A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results i...
CVE-2018-5090Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corruption and we presume t...
CVE-2018-5089Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corrup...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now