2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9265 | — | — | 2.2% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-tn3270.c has a memory leak. |
| CVE-2018-9264 | — | — | 2.7% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the ADB dissector could crash with a heap-based buffer overflow. This w... |
| CVE-2018-9263 | — | — | 2.6% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could crash. This was addressed in epan/dissecto... |
| CVE-2018-9262 | — | — | 2.3% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/p... |
| CVE-2018-9261 | — | — | 2.9% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-... |
| CVE-2018-9260 | — | — | 2.6% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dis... |
| CVE-2018-9259 | — | — | 2.3% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/fi... |
| CVE-2018-9258 | — | — | 2.0% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preser... |
| CVE-2018-9257 | — | — | 1.9% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5, the CQL dissector could go into an infinite loop. This was addressed in epan/dissectors/pac... |
| CVE-2018-9256 | — | — | 2.3% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash. This was addressed in epan/dissectors/... |
| CVE-2018-9238 | — | — | 2.3% | Apr 4, 2018 | proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter. |
| CVE-2018-9237 | — | — | 1.9% | Apr 4, 2018 | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field. |
| CVE-2018-9236 | — | — | 1.9% | Apr 4, 2018 | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field. |
| CVE-2018-9235 | — | — | 2.6% | Apr 4, 2018 | iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php. |
| CVE-2018-9252 | — | — | 2.1% | Apr 4, 2018 | JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/j... |
| CVE-2018-9251 | — | — | 2.4% | Apr 4, 2018 | The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of... |
| CVE-2018-9247 | — | — | 1.6% | Apr 4, 2018 | The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execu... |
| CVE-2018-9234 | — | — | 2.1% | Apr 4, 2018 | GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key... |
| CVE-2018-8941 | — | — | 6.9% | Apr 3, 2018 | Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authentica... |
| CVE-2018-8780 | — | — | 10.1% | Apr 3, 2018 | In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir... |
| CVE-2018-8779 | — | — | 7.2% | Apr 3, 2018 | In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.op... |
| CVE-2018-8778 | — | — | 7.8% | Apr 3, 2018 | In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker contr... |
| CVE-2018-8777 | — | — | 4.6% | Apr 3, 2018 | In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can p... |
| CVE-2018-8049 | — | — | 1.4% | Apr 3, 2018 | The Stealth endpoint in Unisys Stealth SVG 2.8.x, 3.0.x before 3.0.1999, 3.1.x, 3.2.x before 3.2.030, and 3.3.x before 3... |
| CVE-2018-6914 | — | — | 10.6% | Apr 3, 2018 | Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now