2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5101 | — | — | 1.8% | Jun 11, 2018 | A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potent... |
| CVE-2018-5100 | — | — | 5.4% | Jun 11, 2018 | A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while... |
| CVE-2018-5099 | — | — | 3.1% | Jun 11, 2018 | A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that h... |
| CVE-2018-5098 | — | — | 3.1% | Jun 11, 2018 | A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script conte... |
| CVE-2018-5097 | — | — | 7.3% | Jun 11, 2018 | A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is m... |
| CVE-2018-5096 | — | — | 3.0% | Jun 11, 2018 | A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exp... |
| CVE-2018-5095 | — | — | 4.3% | Jun 11, 2018 | An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at l... |
| CVE-2018-5094 | — | — | 15.4% | Jun 11, 2018 | A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called followed by garbage collec... |
| CVE-2018-5093 | — | — | 20.0% | Jun 11, 2018 | A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially e... |
| CVE-2018-5092 | — | — | 1.8% | Jun 11, 2018 | A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of fr... |
| CVE-2018-5091 | — | — | 3.4% | Jun 11, 2018 | A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results i... |
| CVE-2018-5090 | — | — | 2.3% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corruption and we presume t... |
| CVE-2018-5089 | — | — | 3.3% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corrup... |
| CVE-2018-6515 | — | — | 0.8% | Jun 11, 2018 | Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Window... |
| CVE-2018-6514 | — | — | 0.8% | Jun 11, 2018 | In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on... |
| CVE-2018-6513 | — | — | 1.1% | Jun 11, 2018 | Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x ... |
| CVE-2018-6512 | — | — | 1.9% | Jun 11, 2018 | The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. ... |
| CVE-2018-12112 | — | — | 1.3% | Jun 11, 2018 | md_build_attribute in md4c.c in md4c 0.2.6 allows remote attackers to cause a denial of service (Segmentation fault and ... |
| CVE-2018-12111 | — | — | 2.5% | Jun 11, 2018 | Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra... |
| CVE-2018-12110 | — | — | 1.1% | Jun 11, 2018 | portfolioCMS 1.0.5 has SQL Injection via the admin/portfolio.php preview parameter. |
| CVE-2018-12109 | — | — | 1.4% | Jun 11, 2018 | An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC<FileIO>::process function in tra... |
| CVE-2018-12108 | — | — | 1.2% | Jun 11, 2018 | An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attacke... |
| CVE-2018-12102 | — | — | 0.8% | Jun 11, 2018 | md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block. |
| CVE-2018-12100 | — | — | 1.3% | Jun 11, 2018 | Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI. |
| CVE-2018-12099 | — | — | 2.1% | Jun 11, 2018 | Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now