Skip to main content

Year archive

CVEs published in 2018

Archive summary

16,510 CVEs published in 2018 — 2,545 Critical, 7,428 High, 6,299 Medium, 238 Low, 0 Unrated.

CVE-2018-17192

Published Dec 19, 2018

The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results inc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16883

Published Dec 19, 2018

sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were s…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-20231

Published Dec 19, 2018

Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20230

Published Dec 19, 2018

An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a de…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20227

Published Dec 19, 2018

RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19829

Published Dec 18, 2018

Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19789

Published Dec 18, 2018

An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the sca…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17777

Published Dec 18, 2018

An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the default Parental Control PIN (0000), it is possible to bypass the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6978

Published Dec 18, 2018

vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vulnerability due to improper pe…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20213

Published Dec 18, 2018

wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via a long name. NOTE: this is not a Microsoft product.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19522

Published Dec 18, 2018

DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x800020F4) with a buffer containing user defined content. The driver's subroutine…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15031

Published Dec 18, 2018

In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1833

Published Dec 18, 2018

IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An attacker, who has already gained authorised access via the CL…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-4015

Published Dec 18, 2018

An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not enforce a secure connection by d…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-20201

Published Dec 18, 2018

There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a denial of service or possibly unspecified other impact via a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 501-525 of 16,510 CVEsPage 21 of 661