2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5157 | — | — | 1.6% | Jun 11, 2018 | Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for th... |
| CVE-2018-5155 | — | — | 3.5% | Jun 11, 2018 | A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a... |
| CVE-2018-5154 | — | — | 3.3% | Jun 11, 2018 | A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This result... |
| CVE-2018-5153 | — | — | 1.7% | Jun 11, 2018 | If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can res... |
| CVE-2018-5152 | — | — | 1.7% | Jun 11, 2018 | WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com ... |
| CVE-2018-5151 | — | — | 2.8% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume t... |
| CVE-2018-5150 | — | — | 3.2% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed eviden... |
| CVE-2018-5148 | — | — | 3.0% | Jun 11, 2018 | A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used... |
| CVE-2018-5147 | — | — | 2.5% | Jun 11, 2018 | The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Andro... |
| CVE-2018-5146 | — | — | 12.1% | Jun 11, 2018 | An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerab... |
| CVE-2018-5145 | — | — | 3.0% | Jun 11, 2018 | Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume tha... |
| CVE-2018-5144 | — | — | 3.3% | Jun 11, 2018 | An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parame... |
| CVE-2018-5143 | — | — | 0.9% | Jun 11, 2018 | URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scri... |
| CVE-2018-5142 | — | — | 1.2% | Jun 11, 2018 | If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission not... |
| CVE-2018-5141 | — | — | 1.6% | Jun 11, 2018 | A vulnerability in the notifications Push API where notifications can be sent through service workers by web content wit... |
| CVE-2018-5140 | — | — | 1.3% | Jun 11, 2018 | Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise p... |
| CVE-2018-5138 | — | — | 1.1% | Jun 11, 2018 | A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Cust... |
| CVE-2018-5137 | — | — | 1.7% | Jun 11, 2018 | A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. Thi... |
| CVE-2018-5136 | — | — | 1.6% | Jun 11, 2018 | A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing th... |
| CVE-2018-5135 | — | — | 1.5% | Jun 11, 2018 | WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject script... |
| CVE-2018-5134 | — | — | 1.7% | Jun 11, 2018 | WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache",... |
| CVE-2018-5133 | — | — | 1.5% | Jun 11, 2018 | If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this... |
| CVE-2018-5132 | — | — | 1.5% | Jun 11, 2018 | The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a... |
| CVE-2018-5131 | — | — | 2.3% | Jun 11, 2018 | Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-s... |
| CVE-2018-5130 | — | — | 2.4% | Jun 11, 2018 | When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially expl... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now