CVEs from 2018

3,289 normalized CVEs published or assigned in this year.

Total
3,289
critical
critical 225
high
high 266
medium
medium 224
low
low 32
% Critical
6.8%
% with KEV
2.7%
% with exploit
2.8%

Top products

  • erpnext 4
  • terminal_services_manager 1
  • ultraiso 1
  • dolibarr_erp\/crm 1
  • gitbucket 1
  • pdfunite 1
  • qemu 1
  • virtualization_manager 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2018-18348 critical 9.5 multiple issues in chromium archdebian
CVE-2018-17474 critical 9.5 multiple issues in chromium arch
CVE-2018-12398 critical 9.5 By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63. archdebian
CVE-2018-17475 critical 9.5 multiple issues in chromium arch
CVE-2018-17471 critical 9.5 multiple issues in chromium arch
CVE-2018-12390 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enoug… archsusedebian
CVE-2018-19625 critical 9.5 In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_composite.c by preventing a heap-based buffer over-read. archsusedebian
CVE-2018-6110 critical 9.5 multiple issues in chromium arch
CVE-2018-6085 critical 9.5 multiple issues in chromium arch
CVE-2018-12392 critical 9.5 When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects… archsusedebian
CVE-2018-12373 critical 9.5 dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9. archsusedebian
CVE-2018-18359 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18351 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18506 critical 9.5 When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to … archsusedebian
CVE-2018-12385 critical 9.5 A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination w… archsusedebian
CVE-2018-6090 critical 9.5 multiple issues in chromium arch
CVE-2018-6093 critical 9.5 multiple issues in chromium arch
CVE-2018-5152 critical 9.5 WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For exa… archdebian
CVE-2018-6096 critical 9.5 multiple issues in chromium arch
CVE-2018-6114 critical 9.5 multiple issues in chromium arch
CVE-2018-6092 critical 9.5 multiple issues in chromium arch
CVE-2018-12358 critical 9.5 Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malicious site to read responses which are supposed to be opaque. This vulnerability … archsusedebian
CVE-2018-5764 critical 9.5 The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection me… archsusedebian
CVE-2018-6089 critical 9.5 multiple issues in chromium arch
CVE-2018-18337 critical 9.5 multiple issues in chromium archdebian
CVE-2018-1000085 critical 9.5 ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit cha… archsusedebian
CVE-2018-5162 critical 9.5 Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. archdebian
CVE-2018-18492 critical 9.5 A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. T… archsusedebian
CVE-2018-6105 critical 9.5 multiple issues in chromium arch
CVE-2018-18338 critical 9.5 multiple issues in chromium archdebian
CVE-2018-5187 critical 9.5 Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to ru… archsusedebian
CVE-2018-11233 critical 9.5 In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory. archdebian
CVE-2018-12401 critical 9.5 Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnera… archdebian
CVE-2018-11354 critical 9.5 In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed in epan/dissectors/packet-ieee1905.c by making a certain correction to string handling. archsusedebian
CVE-2018-18505 critical 9.5 An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This … archsusedebian
CVE-2018-5176 critical 9.5 The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains malicious JavaScript script embedded as "javascript:" link… archdebian
CVE-2018-18354 critical 9.5 multiple issues in chromium archdebian
CVE-2018-6115 critical 9.5 multiple issues in chromium arch
CVE-2018-5167 critical 9.5 The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, clickable hyperlinks in their output. Web sites should not be … archdebian
CVE-2018-5163 critical 9.5 If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode… archdebian
CVE-2018-5166 critical 9.5 WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have exp… archdebian
CVE-2018-1000222 critical 9.5 Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted … archsusedebian
CVE-2018-18355 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18343 critical 9.5 multiple issues in chromium archdebian
CVE-2018-5175 critical 9.5 A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target website contains an HTML injection flaw an attacker could i… archdebian
CVE-2018-6087 critical 9.5 multiple issues in chromium arch
CVE-2018-17464 critical 9.5 multiple issues in chromium arch
CVE-2018-18336 critical 9.5 multiple issues in chromium archdebian
CVE-2018-6118 critical 9.5 arbitrary code execution in chromium arch
CVE-2018-12399 critical 9.5 When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approvin… archdebian
CVE-2018-19622 critical 9.5 In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse.c by preventing length overflows. archsusedebian
CVE-2018-18649 critical 9.5 multiple issues in gitlab arch
CVE-2018-18357 critical 9.5 multiple issues in chromium archdebian
CVE-2018-12362 critical 9.5 An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploitable crash. This vulnerability affects … archsusedebian
CVE-2018-12372 critical 9.5 Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 52.9. archsusedebian
CVE-2018-17469 critical 9.5 multiple issues in chromium arch
CVE-2018-18352 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18349 critical 9.5 multiple issues in chromium archdebian
CVE-2018-15686 critical 9.5 A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution an… archsusedebian
CVE-2018-18346 critical 9.5 multiple issues in chromium archdebian
CVE-2018-6094 critical 9.5 multiple issues in chromium arch
CVE-2018-18335 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2018-12364 critical 9.5 NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious sit… archsusedebian
CVE-2018-18345 critical 9.5 multiple issues in chromium archdebian
CVE-2018-11360 critical 9.5 In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epan/dissectors/packet-gsm_a_dtap.c by fixing an off-by-one error that caused a bu… archsusedebian
CVE-2018-17476 critical 9.5 multiple issues in chromium arch
CVE-2018-12367 critical 9.5 In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTimi… archsusedebian
CVE-2018-18342 critical 9.5 multiple issues in chromium archdebian
CVE-2018-6099 critical 9.5 multiple issues in chromium arch
CVE-2018-18339 critical 9.5 multiple issues in chromium archdebian
CVE-2018-12374 critical 9.5 Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9. archsusedebian
CVE-2018-5179 critical 9.5 multiple issues in chromium arch
CVE-2018-5181 critical 9.5 If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local file corresponding to the dropped URL, contrary to p… archdebian
CVE-2018-12371 critical 9.5 An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting i… archsusedebian
CVE-2018-11361 critical 9.5 In Wireshark 2.6.0, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/dot11decrypt.c by avoiding a buffer overflow during FTE processing in Dot11DecryptTDLSDeriveKey. archsusedebian
CVE-2018-12369 critical 9.5 WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects… archsusedebian
CVE-2018-12370 critical 9.5 In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, … archsusedebian
CVE-2018-12363 critical 9.5 A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node being freed but the node still having a… archsusedebian
CVE-2018-19627 critical 9.5 In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary. archdebian
CVE-2018-19624 critical 9.5 In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/packet-pvfs2.c by preventing a NULL pointer dereference. archsusedebian
CVE-2018-19626 critical 9.5 In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' termination. archsusedebian
CVE-2018-12397 critical 9.5 A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to … archsusedebian
CVE-2018-12386 critical 9.5 A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process whe… archsusedebian
CVE-2018-5188 critical 9.5 Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could… archsusedebian
CVE-2018-5184 critical 9.5 Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. archdebian
CVE-2018-17467 critical 9.5 multiple issues in chromium arch
CVE-2018-6102 critical 9.5 multiple issues in chromium arch
CVE-2018-6104 critical 9.5 multiple issues in chromium arch
CVE-2018-6107 critical 9.5 multiple issues in chromium arch
CVE-2018-6108 critical 9.5 multiple issues in chromium arch
CVE-2018-6103 critical 9.5 multiple issues in chromium arch
CVE-2018-6111 critical 9.5 multiple issues in chromium arch
CVE-2018-18646 critical 9.5 multiple issues in gitlab arch
CVE-2018-18643 critical 9.5 multiple issues in gitlab arch
CVE-2018-5154 critical 9.5 A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < … archdebian
CVE-2018-5185 critical 9.5 Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. archdebian
CVE-2018-5170 critical 9.5 It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. Thi… archdebian
CVE-2018-18509 critical 9.5 A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signatur… archdebian
CVE-2018-5161 critical 9.5 Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. archdebian
CVE-2018-12389 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s… archdebian