Skip to main content

Year archive

CVEs published in 2018

Archive summary

16,510 CVEs published in 2018 — 2,545 Critical, 7,428 High, 6,299 Medium, 238 Low, 0 Unrated.

CVE-2018-6333

Published Dec 31, 2018

The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML an…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6331

Published Dec 31, 2018

Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6347

Published Dec 31, 2018

An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6346

Published Dec 31, 2018

A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6344

Published Dec 31, 2018

A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulnerability can be used to cause denial of service. It affects…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6343

Published Dec 31, 2018

Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTT…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6342

Published Dec 31, 2018

react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not pr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6341

Published Dec 31, 2018

React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6340

Published Dec 31, 2018

The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This aff…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6337

Published Dec 31, 2018

folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) resul…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6336

Published Dec 31, 2018

An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat bi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6335

Published Dec 31, 2018

A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of H…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6334

Published Dec 31, 2018

Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unex…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-20623

Published Dec 31, 2018

In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archive function in readelf.c via a crafted ELF file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6668

Published Dec 31, 2018

A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows execution bypass, for example, with simple DLL through interpreters such as…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19937

Published Dec 31, 2018

A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19918

Published Dec 31, 2018

CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 16,510 CVEsPage 1 of 661