2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-5129A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages...
CVE-2018-5128A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operatio...
CVE-2018-5127A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentiall...
CVE-2018-5126Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corruption and we presume t...
CVE-2018-5125Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corrup...
CVE-2018-5122A potential integer overflow in the "DoCrypt" function of WebCrypto was identified. If a means was found of exploiting i...
CVE-2018-5121Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When use...
CVE-2018-5119The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin cont...
CVE-2018-5118The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta ...
CVE-2018-5117If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to sc...
CVE-2018-5116WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames ...
CVE-2018-5115If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed ...
CVE-2018-5114If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible throug...
CVE-2018-5113The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but thi...
CVE-2018-5112Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension ma...
CVE-2018-5111When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoo...
CVE-2018-5110If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rend...
CVE-2018-5109An audio capture session can started under an incorrect origin from the site making the capture request. Users are still...
CVE-2018-5108A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data...
CVE-2018-5107The printing process can bypass local access protections to read files available through symlinks, bypassing local file ...
CVE-2018-5106Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a ...
CVE-2018-5105WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an ...
CVE-2018-5104A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, res...
CVE-2018-5103A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This resul...
CVE-2018-5102A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potent...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now