2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12395 | — | — | 2.9% | Feb 28, 2019 | By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through d... |
| CVE-2018-12393 | — | — | 3.9% | Feb 28, 2019 | A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an in... |
| CVE-2018-12392 | — | — | 3.4% | Feb 28, 2019 | When manipulating user events in nested loops while opening a document through script, it is possible to trigger a poten... |
| CVE-2018-12391 | — | — | 2.1% | Feb 28, 2019 | During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of secur... |
| CVE-2018-12390 | — | — | 3.2% | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of... |
| CVE-2018-12389 | — | — | 2.3% | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs sho... |
| CVE-2018-12388 | — | — | 1.4% | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of these bugs showed ev... |
| CVE-2018-20244 | — | — | 2.0% | Feb 27, 2019 | In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database... |
| CVE-2018-20797 | — | — | 1.4% | Feb 27, 2019 | An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofo_calloc in b... |
| CVE-2018-20796 | — | — | 5.8% | Feb 26, 2019 | In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled ... |
| CVE-2018-20063 | — | — | 2.7% | Feb 25, 2019 | An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the imag... |
| CVE-2018-15777 | — | — | — | Feb 25, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-5839 | — | — | 0.2% | Feb 25, 2019 | Improperly configured memory protection allows read/write access to modem image from HLOS kernel in Snapdragon Auto, Sna... |
| CVE-2018-13914 | — | — | 0.2% | Feb 25, 2019 | Lack of input validation for data received from user space can lead to an out of bound array issue in Snapdragon Auto, S... |
| CVE-2018-13913 | — | — | 0.2% | Feb 25, 2019 | Improper validation of array index can lead to unauthorized access while processing debugFS in Snapdragon Auto, Snapdrag... |
| CVE-2018-13912 | — | — | 0.2% | Feb 25, 2019 | Arbitrary write issue can occur when user provides kernel address in compat mode in Snapdragon Auto, Snapdragon Connecti... |
| CVE-2018-13905 | — | — | 0.3% | Feb 25, 2019 | KGSL syncsource lock not handled properly during syncsource cleanup can lead to use after free issue in Snapdragon Auto,... |
| CVE-2018-13904 | — | — | 1.3% | Feb 25, 2019 | Improper input validation in SCM handler to access storage in TZ can lead to unauthorized access in Snapdragon Auto, Sna... |
| CVE-2018-13900 | — | — | 0.3% | Feb 25, 2019 | Use-after-free vulnerability will occur as there is no protection for the route table`s rule in IPA driver in Snapdragon... |
| CVE-2018-11948 | — | — | 0.2% | Feb 25, 2019 | Exceeding the limit of usage entries are not tracked and the information will be lost causing the content to lose contin... |
| CVE-2018-11945 | — | — | 1.4% | Feb 25, 2019 | Improper input validation in wireless service messaging module for data received from broadcast messages can lead to hea... |
| CVE-2018-11938 | — | — | 0.2% | Feb 25, 2019 | Improper input validation for argument received from HLOS can lead to buffer overflows and unexpected behavior in Snapdr... |
| CVE-2018-11935 | — | — | 0.8% | Feb 25, 2019 | Improper input validation might result in incorrect app id returned to the caller Instead of returning failure in Snapdr... |
| CVE-2018-11932 | — | — | 1.1% | Feb 25, 2019 | Improper input validation can lead RW access to secure subsystem from HLOS in Snapdragon Auto, Snapdragon Compute, Snapd... |
| CVE-2018-11931 | — | — | 0.2% | Feb 25, 2019 | Improper access to HLOS is possible while transferring memory to CPZ in Snapdragon Auto, Snapdragon Compute, Snapdragon ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now