2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14636 | MEDIUM | 5.3 | 1.2% | Sep 10, 2018 | Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief windo... |
| CVE-2018-14635 | MEDIUM | 6.5 | 2.5% | Sep 10, 2018 | When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an... |
| CVE-2018-14620 | MEDIUM | 4.7 | 0.6% | Sep 10, 2018 | The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build ... |
| CVE-2018-14625 | MEDIUM | 5.3 | 0.3% | Sep 10, 2018 | A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from wi... |
| CVE-2018-16750 | MEDIUM | 6.5 | 2.9% | Sep 9, 2018 | In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/meta.c was found. |
| CVE-2018-16749 | MEDIUM | 6.5 | 2.3% | Sep 9, 2018 | In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause... |
| CVE-2018-1757 | MEDIUM | 5.3 | 1.7% | Sep 7, 2018 | IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive informat... |
| CVE-2018-16517 | MEDIUM | 5.5 | 5.2% | Sep 6, 2018 | asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni... |
| CVE-2018-10930 | MEDIUM | 6.5 | 2.1% | Sep 4, 2018 | A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw... |
| CVE-2018-10924 | MEDIUM | 5.3 | 1.9% | Sep 4, 2018 | It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use t... |
| CVE-2018-10914 | MEDIUM | 6.5 | 2.4% | Sep 4, 2018 | It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash whi... |
| CVE-2018-10913 | MEDIUM | 6.5 | 2.1% | Sep 4, 2018 | An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via ... |
| CVE-2018-14627 | MEDIUM | 5.3 | 1.1% | Sep 4, 2018 | The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required... |
| CVE-2018-16362 | MEDIUM | 6.1 | 1.6% | Sep 2, 2018 | An issue was discovered in the Source Integration plugin before 1.5.9 and 2.x before 2.1.5 for MantisBT. A cross-site sc... |
| CVE-2018-16323 | MEDIUM | 6.5 | 49.3% | Sep 1, 2018 | ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha... |
| CVE-2018-11057 | MEDIUM | 5.9 | 1.7% | Aug 31, 2018 | RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Tim... |
| CVE-2018-11056 | MEDIUM | 6.5 | 1.9% | Aug 31, 2018 | RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5... |
| CVE-2018-11055 | MEDIUM | 5.5 | 0.4% | Aug 31, 2018 | RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper... |
| CVE-2018-14621 | MEDIUM | 5.3 | 2.3% | Aug 30, 2018 | An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than s... |
| CVE-2018-7795 | MEDIUM | 5.4 | 2.3% | Aug 29, 2018 | A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) pr... |
| CVE-2018-12240 | MEDIUM | 5.9 | 1.1% | Aug 29, 2018 | The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded ... |
| CVE-2018-15746 | MEDIUM | 5.5 | 0.5% | Aug 29, 2018 | qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishand... |
| CVE-2018-16062 | MEDIUM | 5.5 | 1.7% | Aug 29, 2018 | dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial ... |
| CVE-2018-15740 | MEDIUM | 6.1 | 6.1% | Aug 28, 2018 | Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen. |
| CVE-2018-3926 | MEDIUM | 5.5 | 0.4% | Aug 28, 2018 | An exploitable integer underflow vulnerability exists in the ZigBee firmware update routine of the hubCore binary of the... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now