Skip to main content

Year archive

CVEs published in 2018

Archive summary

16,510 CVEs published in 2018 — 2,545 Critical, 7,428 High, 6,299 Medium, 238 Low, 0 Unrated.

CVE-2018-5294

Published Jan 8, 2018

In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers could leverage this vulnerability…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5284

Published Jan 8, 2018

The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5279

Published Jan 8, 2018

In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not va…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5278

Published Jan 8, 2018

In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not va…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-5277

Published Jan 8, 2018

In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not va…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5276

Published Jan 8, 2018

In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not va…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5275

Published Jan 8, 2018

In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not va…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5274

Published Jan 8, 2018

In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not va…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5273

Published Jan 8, 2018

In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not va…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5272

Published Jan 8, 2018

In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not va…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5271

Published Jan 8, 2018

In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not va…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5270

Published Jan 8, 2018

In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not va…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5269

Published Jan 8, 2018

In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5268

Published Jan 8, 2018

In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3815

Published Jan 8, 2018

The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS Protocol Validation attack th…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5971

Published Jan 8, 2018

SQL injection vulnerability in NewsBee CMS allow remote attackers to execute arbitrary SQL commands.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 16,276-16,300 of 16,510 CVEsPage 652 of 661