Skip to main content

Year archive

CVEs published in 2018

Archive summary

16,510 CVEs published in 2018 — 2,545 Critical, 7,428 High, 6,299 Medium, 238 Low, 0 Unrated.

CVE-2018-1000858

Published Dec 20, 2018

GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000857

Published Dec 20, 2018

log-user-session version 0.7 and earlier contains a Directory Traversal vulnerability in Main SUID-binary /usr/local/bin/log-user-session that can result in User to root privilege…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000856

Published Dec 20, 2018

DomainMOD version 4.09.03 and above. Also verified in the latest version 4.11.01 contains a Cross Site Scripting (XSS) vulnerability in Segment Name field in the segments page tha…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000855

Published Dec 20, 2018

easymon version 1.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Endpoint where monitoring is mounted that can result in Reflected XSS that affects Firefox.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000854

Published Dec 20, 2018

esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-11988

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Un-trusted pointer de-reference issue by accessing a variable which is a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11987

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, if there is an unlikely memory alloc failure for the secure pool in boot…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11986

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possible buffer overflow in TX and RX FIFOs of microcontroller in camera…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11985

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, When allocating heap using user supplied size, Possible heap overflow vu…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11984

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, A use after free condition and an out-of-bounds access can occur in the…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11983

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Error in kernel observed while accessing freed mask pointers after reall…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11965

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Anyone can execute proptrigger.sh which will lead to change in propertie…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11964

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Exposing the hashed content in /etc/passwd may lead to security issue.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11963

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Buffer overread may occur due to non-null terminated strings while proce…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11961

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possibility of accessing out of bound vector index When updating some GN…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11960

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, A use after free condition can occur in the SPS driver which can lead to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000851

Published Dec 20, 2018

Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' private key can be compromised.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000850

Published Dec 20, 2018

Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000849

Published Dec 20, 2018

Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000848

Published Dec 20, 2018

Wampserver version prior to version 3.1.5 contains a Cross Site Scripting (XSS) vulnerability in index.php localhost page that can result in very low. This attack appear to be exp…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000847

Published Dec 20, 2018

FreshDNS version 1.0.3 and prior contains a Cross Site Scripting (XSS) vulnerability in Account data form; Zone editor that can result in Execution of attacker's JavaScript code i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000846

Published Dec 20, 2018

FreshDNS version 1.0.3 and earlier contains a Cross ite Request Forgery (CSRF) vulnerability in All (authenticated) API calls in index.php / class.manager.php that can result in E…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000844

Published Dec 20, 2018

Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JAXB that can result in An attac…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000843

Published Dec 20, 2018

Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 contains a Cross ite Request Forgery (CSRF) vu…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 401-425 of 16,510 CVEsPage 17 of 661