CVEs from 2018

3,719 normalized CVEs published or assigned in this year.

Total
3,719
critical
critical 225
high
high 266
medium
medium 224
low
low 32
% Critical
6.1%
% with KEV
2.4%
% with exploit
2.4%

Top products

  • erpnext 4
  • terminal_services_manager 1
  • ultraiso 1
  • dolibarr_erp\/crm 1
  • gitbucket 1
  • pdfunite 1
  • qemu 1
  • virtualization_manager 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2018-16858 high 8.0 It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could… archsusedebian
CVE-2018-8905 high 8.0 In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps. archsusedebian
CVE-2018-5784 high 8.0 In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a cr… archsusedebian
CVE-2018-20175 high 8.0 rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result in a Denial of Service (segfault). archdebian
CVE-2018-14665 high 8.0 A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in… archsusedebian
CVE-2018-5744 high 8.0 A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, a… debianarchsuse
CVE-2018-1000880 high 8.0 libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read… archsusedebian
CVE-2018-8007 high 8.0 arbitrary code execution in couchdb archsuse
CVE-2018-17407 high 8.0 An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution wh… archsusedebian
CVE-2018-16852 high 8.0 Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of an DNS zone in the DNS management DCE/RPC server, the internal DNS server or t… archsusedebian
CVE-2018-6791 high 8.0 An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted th… archdebian
CVE-2018-7054 high 8.0 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix fo… archdebian
CVE-2018-20002 high 8.0 The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading t… debianarchsuse
CVE-2018-7051 high 8.0 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. Certain nick names could result in out-of-bounds access when printing theme strings. archdebian
CVE-2018-18557 high 8.0 LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (with JBIG enabled) de… archsusedebian
CVE-2018-15664 high 8.0 In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access t… archsusedebian
CVE-2018-16865 high 8.0 An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A loca… archsusedebian
CVE-2018-1000877 high 8.0 libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_form… archsusedebian
CVE-2018-1100 high 8.0 zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the context of another… archsusedebian
CVE-2018-14361 high 8.0 An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data. archdebian
CVE-2018-1121 high 8.0 procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can us… archsusedebian
CVE-2018-14526 high 8.0 An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker … archsusedebian
CVE-2018-7254 high 8.0 The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a buffer overflow or in… archsusedebian
CVE-2018-14912 high 8.0 cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request. archdebian
CVE-2018-14403 high 8.0 multiple issues in libmp4v2 arch
CVE-2018-7456 high 8.0 A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.… archsusedebian
CVE-2018-6574 high 8.0 4y ago Remote command execution via "go get" command with cgo in cmd/go archgolang
CVE-2018-16873 high 8.0 4y ago Remote command execution via "go get" with "-u" flag in cmd/go archsusegolang
CVE-2018-16874 high 8.0 4y ago Directory traversal via "go get" command in cmd/go archsusegolang
CVE-2018-16875 high 8.0 4y ago Denial of service in chain verification in crypto/x509 archsusegolang
CVE-2018-20303 high 8.0 4y ago Gogs Directory Traversal golang
CVE-2018-1999006 high 8.0 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Jenkins archjava
CVE-2018-7408 high 8.0 4y ago An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g npm" command, and also announced in the vendor's bl… archdebiannpm
CVE-2018-1999004 high 8.0 4y ago Incorrect Authorization in Jenkins archjava
CVE-2018-1999002 high 8.0 4y ago Improper Input Validation in Jenkins archjava
CVE-2018-1999007 high 8.0 4y ago Cross-site scripting vulnerability exists in Jenkins and Stapler Plugin archjava
CVE-2018-1999005 high 8.0 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins archjava
CVE-2018-1999001 high 8.0 4y ago Improper Input Validation in Jenkins archjava
CVE-2018-1999003 high 8.0 4y ago Incorrect Authorization in Jenkins archjava
CVE-2018-25032 high 8.0 4y ago Important: mingw-zlib security update rockylinuxredhatarchsuse+2
CVE-2018-8037 high 8.0 8y ago Apache Tomcat Race Condition vulnerability suserockylinuxdebianjava
CVE-2018-8034 high 8.0 8y ago The host name verification missing in Apache Tomcat suserockylinuxdebianjava
CVE-2018-8014 high 8.0 8y ago Important: pki-deps:10.6 security update suserockylinuxdebianjava
CVE-2018-11784 high 8.0 8y ago Apache Tomcat Open Redirect vulnerability suserockylinuxdebianjava
CVE-2018-12086 high 8.0 8y ago Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests. archsusedebiannuget
CVE-2018-25302 high 7.8 7.8 29d ago Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a ma…
CVE-2018-25261 high 7.8 7.8 1mo ago Iperius Backup 5.8.1 contains a local buffer overflow vulnerability in the structured exception handling (SEH) mechanism that allows local attackers to execute arbitrary code by supplying a malicious…
CVE-2018-25260 high 7.8 7.8 1mo ago MAGIX Music Editor 3.1 contains a buffer overflow vulnerability in the FreeDB Proxy Options dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. A…
CVE-2018-25259 high 7.8 7.8 1mo ago Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering structured exception…
CVE-2018-25213 high 7.8 7.8 2mo ago Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. At…
CVE-2018-6400 high 7.8 7.8 8y ago Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \\.\pipe\WPSCloudSvr\WpsCloudSvr -- an "insecur…
CVE-2018-25374 high 7.5 7.5 3d ago Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers …
CVE-2018-25368 high 7.5 7.5 3d ago Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers ca…
CVE-2018-25365 high 7.5 7.5 3d ago PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting relative path sequences in GET requests. Attackers can use pat…
CVE-2018-25358 high 7.5 7.5 5d ago D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by manipulating the table_name parameter in POST req…
CVE-2018-25329 high 7.5 7.5 11d ago WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attack…
CVE-2018-25326 high 7.5 7.5 11d ago Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parame…
CVE-2018-25325 high 7.5 7.5 11d ago Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX …
CVE-2018-17958 high 7.5 7.5 8y ago Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used. susedebianubunturedhat
CVE-2018-25381 high 7.1 7.1 3d ago Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can injec…
CVE-2018-25380 high 7.1 7.1 3d ago Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, and filter_s…
CVE-2018-25352 high 7.1 7.1 5d ago WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code th…
CVE-2018-25347 high 7.1 7.1 5d ago WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv_f…
CVE-2018-25346 high 7.1 7.1 5d ago WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMa…
CVE-2018-25319 high 7.1 7.1 11d ago Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter. Att…
CVE-2018-25207 high 7.1 7.1 2mo ago Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated attackers to execute arbitrary SQL commands. Attackers can submit malicious POS…
CVE-2018-25361 medium 6.8 6.8 3d ago Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption k…
CVE-2018-10622 medium 6.8 6.8 8y ago Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.
CVE-2018-25312 medium 6.5 6.5 29d ago LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interfac…
CVE-2018-25311 medium 6.5 6.5 29d ago VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers with valid credentials to disclose arbitrary files by injecting path trav…
CVE-2018-25378 medium 6.2 6.2 3d ago Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the notebook name field. Attackers can crea…
CVE-2018-25369 medium 6.2 6.2 3d ago Visual Ping 0.8.0.0 contains a buffer overflow vulnerability in input field handling that allows local attackers to crash the application by supplying oversized data. Attackers can inject malicious p…
CVE-2018-25367 medium 6.2 6.2 3d ago NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can tri…
CVE-2018-25324 medium 6.2 6.2 11d ago Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes into the wp_abspat…
CVE-2018-25313 medium 6.2 6.2 29d ago SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers to cause a denial of service by supplying an oversized string. Attackers can in…
CVE-2018-25305 medium 6.2 6.2 29d ago librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service by processing malformed SVG files. Attackers can supply crafted SVG input to the…
CVE-2018-25349 medium 6.1 6.1 5d ago userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP header. Attackers can send crafted requests to the ba…
CVE-2018-25331 medium 6.1 6.1 11d ago Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attac…
CVE-2018-25309 medium 6.1 6.1 29d ago MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can creat…
CVE-2018-25269 medium 6.1 6.1 1mo ago ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed …
CVE-2018-25247 medium 6.1 6.1 2mo ago MyBB Like Plugin 3.0.0 contains a stored cross-site scripting vulnerability. Authenticated attackers can inject script payloads into post or thread subjects; when other users view a profile that disp…
CVE-2018-18520 medium 5.5 An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes… archsusedebian
CVE-2018-12543 medium 5.5 In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert is triggered that … archdebian
CVE-2018-5206 medium 5.5 When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer. archdebian
CVE-2018-1125 medium 5.5 procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is comp… archsusedebian
CVE-2018-16228 medium 5.5 The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix(). suserockylinuxdebian
CVE-2018-7548 medium 5.5 In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result. archdebian
CVE-2018-5208 medium 5.5 In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings. archdebian
CVE-2018-16452 medium 5.5 The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion. suserockylinuxdebian
CVE-2018-5205 medium 5.5 When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string. archdebian
CVE-2018-12327 medium 5.5 Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IP… archsusedebian
CVE-2018-20102 medium 5.5 An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 … archsusedebian
CVE-2018-20103 medium 5.5 An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a lon… archsusedebian
CVE-2018-16451 medium 5.5 The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN. suserockylinuxdebian
CVE-2018-14468 medium 5.5 The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print(). suserockylinuxdebian
CVE-2018-8002 medium 5.5 In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers could leverage this vu… archsusedebian
CVE-2018-14881 medium 5.5 The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART). suserockylinuxdebian
CVE-2018-5709 medium 5.5 An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assig… archsusedebian
CVE-2018-1000007 medium 5.5 libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the hos… archsusedebian
CVE-2018-1301 medium 5.5 multiple issues in apache debianarchsuse