2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-14636MEDIUM5.3Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief windo...
CVE-2018-14635MEDIUM6.5When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an...
CVE-2018-14620MEDIUM4.7The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build ...
CVE-2018-14625MEDIUM5.3A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from wi...
CVE-2018-16750MEDIUM6.5In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/meta.c was found.
CVE-2018-16749MEDIUM6.5In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause...
CVE-2018-1757MEDIUM5.3IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive informat...
CVE-2018-16517MEDIUM5.5asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni...
CVE-2018-10930MEDIUM6.5A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw...
CVE-2018-10924MEDIUM5.3It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use t...
CVE-2018-10914MEDIUM6.5It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash whi...
CVE-2018-10913MEDIUM6.5An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via ...
CVE-2018-14627MEDIUM5.3The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required...
CVE-2018-16362MEDIUM6.1An issue was discovered in the Source Integration plugin before 1.5.9 and 2.x before 2.1.5 for MantisBT. A cross-site sc...
CVE-2018-16323MEDIUM6.5ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha...
CVE-2018-11057MEDIUM5.9RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Tim...
CVE-2018-11056MEDIUM6.5RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5...
CVE-2018-11055MEDIUM5.5RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper...
CVE-2018-14621MEDIUM5.3An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than s...
CVE-2018-7795MEDIUM5.4A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) pr...
CVE-2018-12240MEDIUM5.9The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded ...
CVE-2018-15746MEDIUM5.5qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishand...
CVE-2018-16062MEDIUM5.5dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial ...
CVE-2018-15740MEDIUM6.1Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
CVE-2018-3926MEDIUM5.5An exploitable integer underflow vulnerability exists in the ZigBee firmware update routine of the hubCore binary of the...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now