Skip to main content

Year archive

CVEs published in 2018

Archive summary

16,510 CVEs published in 2018 — 2,545 Critical, 7,428 High, 6,299 Medium, 238 Low, 0 Unrated.

CVE-2017-15883

Published Jan 8, 2018

Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or ga…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-2319

Published Jan 8, 2018

The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK"…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2318

Published Jan 8, 2018

The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake sta…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-7222

Published Jan 8, 2018

Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (application crash) by connecting to a channel with a differe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7221

Published Jan 8, 2018

TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash) by connecting to a channel with a differ…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5509

Published Jan 8, 2018

clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5334

Published Jan 8, 2018

FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-5071

Published Jan 8, 2018

SQL injection vulnerability in the checkPassword function in Symmetricom s350i 2.70.15 allows remote attackers to execute arbitrary SQL commands via vectors involving a username.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-3607

Published Jan 8, 2018

DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2071

Published Jan 8, 2018

Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single poli…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1858

Published Jan 8, 2018

__init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4364

Published Jan 8, 2018

(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impac…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5282

Published Jan 8, 2018

Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML document. NOTE: the vendor disput…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5259

Published Jan 8, 2018

Discuz! DiscuzX X3.4 allows remote authenticated users to bypass intended attachment-deletion restrictions via a modified aid parameter.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5298

Published Jan 8, 2018

In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android, AES encryption with static parameters is used to secure the locally stored shared p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5296

Published Jan 8, 2018

In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PdfParser::ReadXRefSubsection function (base/PdfParser.cpp). Remote attackers could leverage this vulnerability…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5295

Published Jan 8, 2018

In PoDoFo 0.9.5, there is an integer overflow in the PdfXRefStreamParserObject::ParseStream function (base/PdfXRefStreamParserObject.cpp). Remote attackers could leverage this vul…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 16,251-16,275 of 16,510 CVEsPage 651 of 661