2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-5157Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for th...
CVE-2018-5155A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a...
CVE-2018-5154A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This result...
CVE-2018-5153If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can res...
CVE-2018-5152WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com ...
CVE-2018-5151Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume t...
CVE-2018-5150Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed eviden...
CVE-2018-5148A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used...
CVE-2018-5147The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Andro...
CVE-2018-5146An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerab...
CVE-2018-5145Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume tha...
CVE-2018-5144An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parame...
CVE-2018-5143URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scri...
CVE-2018-5142If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission not...
CVE-2018-5141A vulnerability in the notifications Push API where notifications can be sent through service workers by web content wit...
CVE-2018-5140Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise p...
CVE-2018-5138A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Cust...
CVE-2018-5137A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. Thi...
CVE-2018-5136A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing th...
CVE-2018-5135WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject script...
CVE-2018-5134WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache",...
CVE-2018-5133If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this...
CVE-2018-5132The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a...
CVE-2018-5131Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-s...
CVE-2018-5130When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially expl...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now