2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-5184Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbi...
CVE-2018-5183Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues inclu...
CVE-2018-5182If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the a...
CVE-2018-5181If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process...
CVE-2018-5180A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash,...
CVE-2018-5178A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of d...
CVE-2018-5177A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances,...
CVE-2018-5176The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If ...
CVE-2018-5175A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dyn...
CVE-2018-5174In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with ...
CVE-2018-5173The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name t...
CVE-2018-5172The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard in...
CVE-2018-5170It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a use...
CVE-2018-5169If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home p...
CVE-2018-5168Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of ...
CVE-2018-5167The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" ...
CVE-2018-5166WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirec...
CVE-2018-5165MEDIUM5.3In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by de...
CVE-2018-5164Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixe...
CVE-2018-5163If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to ...
CVE-2018-5162Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects ...
CVE-2018-5161Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thu...
CVE-2018-5160WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. Thi...
CVE-2018-5159An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks,...
CVE-2018-5158The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injec...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now