2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5113 | — | — | 2.1% | Jun 11, 2018 | The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but thi... |
| CVE-2018-5112 | — | — | 2.0% | Jun 11, 2018 | Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension ma... |
| CVE-2018-5111 | — | — | 1.6% | Jun 11, 2018 | When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoo... |
| CVE-2018-5110 | — | — | 1.5% | Jun 11, 2018 | If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rend... |
| CVE-2018-5109 | — | — | 0.6% | Jun 11, 2018 | An audio capture session can started under an incorrect origin from the site making the capture request. Users are still... |
| CVE-2018-5108 | — | — | 1.2% | Jun 11, 2018 | A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data... |
| CVE-2018-5107 | — | — | 1.8% | Jun 11, 2018 | The printing process can bypass local access protections to read files available through symlinks, bypassing local file ... |
| CVE-2018-5106 | — | — | 1.3% | Jun 11, 2018 | Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a ... |
| CVE-2018-5105 | — | — | 0.4% | Jun 11, 2018 | WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an ... |
| CVE-2018-5104 | — | — | 7.3% | Jun 11, 2018 | A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, res... |
| CVE-2018-5103 | — | — | 3.1% | Jun 11, 2018 | A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This resul... |
| CVE-2018-5102 | — | — | 7.2% | Jun 11, 2018 | A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potent... |
| CVE-2018-5101 | — | — | 1.8% | Jun 11, 2018 | A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potent... |
| CVE-2018-5100 | — | — | 5.4% | Jun 11, 2018 | A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while... |
| CVE-2018-5099 | — | — | 3.1% | Jun 11, 2018 | A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that h... |
| CVE-2018-5098 | — | — | 3.1% | Jun 11, 2018 | A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script conte... |
| CVE-2018-5097 | — | — | 7.3% | Jun 11, 2018 | A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is m... |
| CVE-2018-5096 | — | — | 3.0% | Jun 11, 2018 | A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exp... |
| CVE-2018-5095 | — | — | 4.3% | Jun 11, 2018 | An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at l... |
| CVE-2018-5094 | — | — | 15.4% | Jun 11, 2018 | A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called followed by garbage collec... |
| CVE-2018-5093 | — | — | 20.0% | Jun 11, 2018 | A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially e... |
| CVE-2018-5092 | — | — | 1.8% | Jun 11, 2018 | A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of fr... |
| CVE-2018-5091 | — | — | 3.4% | Jun 11, 2018 | A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results i... |
| CVE-2018-5090 | — | — | 2.3% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corruption and we presume t... |
| CVE-2018-5089 | — | — | 3.3% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corrup... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now