Skip to main content

Year archive

CVEs published in 2018

Archive summary

16,510 CVEs published in 2018 — 2,545 Critical, 7,428 High, 6,299 Medium, 238 Low, 0 Unrated.

CVE-2018-5267

Published Jan 8, 2018

Cobham Sea Tel 121 build 222701 devices allow remote attackers to bypass authentication via a direct request to MenuDealerGx.html, MenuDealer.html, MenuEuNCGx.html, MenuEuNC.html,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-5253

Published Jan 5, 2018

The AP4_FtypAtom class in Core/Ap4FtypAtom.cpp in Bento4 1.5.1.0 has an Infinite loop via a crafted MP4 file that triggers size mishandling.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5252

Published Jan 5, 2018

libimageworsener.a in ImageWorsener 1.3.2, when libjpeg 8d is used, has a large loop in the get_raw_sample_int function in imagew-main.c.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5251

Published Jan 5, 2018

In libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value) in the readSBits function (util/read.c). Remote attackers can leverage this v…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5249

Published Jan 5, 2018

Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18021

Published Jan 5, 2018

It was discovered that QtPass before 1.2.1, when using the built-in password generator, generates possibly predictable and enumerable passwords. This only applies to the QtPass GU…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-5244

Published Jan 5, 2018

In Xen 4.10, new infrastructure was introduced as part of an overhaul to how MSR emulation happens for guests. Unfortunately, one tracking structure isn't freed when a vcpu is des…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16666

Published Jan 5, 2018

Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file. NOTE: this issue can be exploit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8540

Published Jan 5, 2018

The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 16,301-16,325 of 16,510 CVEsPage 653 of 661