2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5184 | — | — | 1.8% | Jun 11, 2018 | Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbi... |
| CVE-2018-5183 | — | — | 3.2% | Jun 11, 2018 | Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues inclu... |
| CVE-2018-5182 | — | — | 2.1% | Jun 11, 2018 | If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the a... |
| CVE-2018-5181 | — | — | 2.5% | Jun 11, 2018 | If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process... |
| CVE-2018-5180 | — | — | 2.3% | Jun 11, 2018 | A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash,... |
| CVE-2018-5178 | — | — | 5.1% | Jun 11, 2018 | A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of d... |
| CVE-2018-5177 | — | — | 3.9% | Jun 11, 2018 | A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances,... |
| CVE-2018-5176 | — | — | 1.4% | Jun 11, 2018 | The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If ... |
| CVE-2018-5175 | — | — | 1.5% | Jun 11, 2018 | A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dyn... |
| CVE-2018-5174 | — | — | 1.9% | Jun 11, 2018 | In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with ... |
| CVE-2018-5173 | — | — | 1.8% | Jun 11, 2018 | The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name t... |
| CVE-2018-5172 | — | — | 1.6% | Jun 11, 2018 | The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard in... |
| CVE-2018-5170 | — | — | 1.8% | Jun 11, 2018 | It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a use... |
| CVE-2018-5169 | — | — | 1.4% | Jun 11, 2018 | If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home p... |
| CVE-2018-5168 | — | — | 2.4% | Jun 11, 2018 | Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of ... |
| CVE-2018-5167 | — | — | 1.4% | Jun 11, 2018 | The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" ... |
| CVE-2018-5166 | — | — | 2.4% | Jun 11, 2018 | WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirec... |
| CVE-2018-5165 | MEDIUM | 5.3 | 1.7% | Jun 11, 2018 | In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by de... |
| CVE-2018-5164 | — | — | 1.6% | Jun 11, 2018 | Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixe... |
| CVE-2018-5163 | — | — | 2.1% | Jun 11, 2018 | If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to ... |
| CVE-2018-5162 | — | — | 2.0% | Jun 11, 2018 | Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects ... |
| CVE-2018-5161 | — | — | 2.1% | Jun 11, 2018 | Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thu... |
| CVE-2018-5160 | — | — | 2.7% | Jun 11, 2018 | WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. Thi... |
| CVE-2018-5159 | — | — | 21.3% | Jun 11, 2018 | An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks,... |
| CVE-2018-5158 | — | — | 10.6% | Jun 11, 2018 | The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injec... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now