2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9270 | — | — | 2.4% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/oids.c has a memory leak. |
| CVE-2018-9269 | — | — | 2.4% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-giop.c has a memory leak. |
| CVE-2018-9268 | — | — | 2.4% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-smb2.c has a memory leak. |
| CVE-2018-9267 | — | — | 2.3% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-lapd.c has a memory leak. |
| CVE-2018-9266 | — | — | 2.1% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-isup.c has a memory leak. |
| CVE-2018-9265 | — | — | 2.2% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-tn3270.c has a memory leak. |
| CVE-2018-9264 | — | — | 2.7% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the ADB dissector could crash with a heap-based buffer overflow. This w... |
| CVE-2018-9263 | — | — | 2.6% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could crash. This was addressed in epan/dissecto... |
| CVE-2018-9262 | — | — | 2.3% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/p... |
| CVE-2018-9261 | — | — | 2.9% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-... |
| CVE-2018-9260 | — | — | 2.6% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dis... |
| CVE-2018-9259 | — | — | 2.3% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/fi... |
| CVE-2018-9258 | — | — | 2.0% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preser... |
| CVE-2018-9257 | — | — | 1.9% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5, the CQL dissector could go into an infinite loop. This was addressed in epan/dissectors/pac... |
| CVE-2018-9256 | — | — | 2.3% | Apr 4, 2018 | In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash. This was addressed in epan/dissectors/... |
| CVE-2018-9238 | — | — | 2.3% | Apr 4, 2018 | proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter. |
| CVE-2018-9237 | — | — | 1.9% | Apr 4, 2018 | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field. |
| CVE-2018-9236 | — | — | 1.9% | Apr 4, 2018 | iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field. |
| CVE-2018-9235 | — | — | 2.6% | Apr 4, 2018 | iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php. |
| CVE-2018-9252 | — | — | 2.1% | Apr 4, 2018 | JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/j... |
| CVE-2018-9251 | — | — | 2.4% | Apr 4, 2018 | The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of... |
| CVE-2018-9247 | — | — | 1.6% | Apr 4, 2018 | The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execu... |
| CVE-2018-9234 | — | — | 2.1% | Apr 4, 2018 | GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key... |
| CVE-2018-8941 | — | — | 6.9% | Apr 3, 2018 | Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authentica... |
| CVE-2018-9240 | HIGH | 7.5 | 1.9% | Apr 3, 2018 | ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and another client sends ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now