2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1398MEDIUM5.3IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain...
CVE-2018-14460An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_sdspa...
CVE-2018-14459An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in pData[0] access in the function store16 in h...
CVE-2018-14458An issue was discovered in libgig 4.1.0. There is a heap-based buffer overflow in pData[1] access in the function store3...
CVE-2018-14457An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in the function DLS::Info::UpdateChunks in DLS....
CVE-2018-14456An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in the function DLS::Info::SaveString in DLS.cp...
CVE-2018-14455An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in pData[0] access in the function store32 in h...
CVE-2018-14454An issue was discovered in libgig 4.1.0. There is an out-of-bounds read in the function RIFF::Chunk::Read in RIFF.cpp.
CVE-2018-14453An issue was discovered in libgig 4.1.0. There is a heap-based buffer overflow in pData[1] access in the function store1...
CVE-2018-14452An issue was discovered in libgig 4.1.0. There is an out-of-bounds read in the "always assign the sample of the first di...
CVE-2018-14451An issue was discovered in libgig 4.1.0. There is a heap-based buffer overflow in the function RIFF::Chunk::Read in RIFF...
CVE-2018-14450An issue was discovered in libgig 4.1.0. There is an out-of-bounds read in the "update dimension region's chunks" featur...
CVE-2018-14449An issue was discovered in libgig 4.1.0. There is an out of bounds read in gig::File::UpdateChunks in gig.cpp.
CVE-2018-14448Codec::parse in track.cpp in Untrunc through 2018-06-07 has a NULL pointer dereference via a crafted MP4 file because of...
CVE-2018-14447trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read.
CVE-2018-14446MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-ba...
CVE-2018-14445In Bento4 v1.5.1-624, AP4_File::ParseStream in Ap4File.cpp allows remote attackers to cause a denial of service (infinit...
CVE-2018-14444libdxfrw 0.6.3 has an Integer Overflow in dwgCompressor::decompress18 in dwgutil.cpp, leading to an out-of-bounds read a...
CVE-2018-14443get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV).
CVE-2018-14442Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4s...
CVE-2018-8018In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowe...
CVE-2018-14422blog/index.php in SansCMS 0.7 has XSS via the q parameter.
CVE-2018-14421SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin...
CVE-2018-14420MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by a...
CVE-2018-14419MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now