CVEs from 2018

3,289 normalized CVEs published or assigned in this year.

Total
3,289
critical
critical 225
high
high 266
medium
medium 224
low
low 32
% Critical
6.8%
% with KEV
2.7%
% with exploit
2.8%

Top products

  • erpnext 4
  • terminal_services_manager 1
  • ultraiso 1
  • dolibarr_erp\/crm 1
  • gitbucket 1
  • pdfunite 1
  • qemu 1
  • virtualization_manager 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2018-14465 medium 5.5 The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print(). suserockylinuxdebian
CVE-2018-14462 medium 5.5 The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print(). suserockylinuxdebian
CVE-2018-14470 medium 5.5 The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2(). suserockylinuxdebian
CVE-2018-14644 medium 5.5 An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DN… archsusedebian
CVE-2018-5206 medium 5.5 When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer. archdebian
CVE-2018-1125 medium 5.5 procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is comp… archsusedebian
CVE-2018-16228 medium 5.5 The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix(). suserockylinuxdebian
CVE-2018-7548 medium 5.5 In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result. archdebian
CVE-2018-14320 medium 5.5 This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo. User interaction is required to exploit this vulnerability in that the target must … archsusedebian
CVE-2018-12983 medium 5.5 A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be leveraged by remote attackers to cause a denial-of-service via … archsusedebian
CVE-2018-12607 medium 5.5 multiple issues in gitlab arch
CVE-2018-12606 medium 5.5 multiple issues in gitlab arch
CVE-2018-19661 medium 5.5 An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of service. archdebian
CVE-2018-19591 medium 5.5 In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related t… archdebian
CVE-2018-17144 medium 5.5 Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (application crash) exploitabl… archsusedebian
CVE-2018-5738 medium 5.5 Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND names… debianarchsuse
CVE-2018-5205 medium 5.5 When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string. archdebian
CVE-2018-6459 medium 5.5 The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that… archsusedebian
CVE-2018-16451 medium 5.5 The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN. suserockylinuxdebian
CVE-2018-14468 medium 5.5 The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print(). suserockylinuxdebian
CVE-2018-8002 medium 5.5 In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers could leverage this vu… archsusedebian
CVE-2018-5207 medium 5.5 When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string. archdebian
CVE-2018-20751 medium 5.5 An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject(… archsusedebian
CVE-2018-5308 medium 5.5 PoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStream.cpp). Remote attackers could leverage this vulnerability to cause a denial-… archsusedebian
CVE-2018-8001 medium 5.5 In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly… archsusedebian
CVE-2018-16229 medium 5.5 The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option(). suserockylinuxdebian
CVE-2018-16300 medium 5.5 The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion. suserockylinuxdebian
CVE-2018-5783 medium 5.5 In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecObjects.h). Remote attackers could leverage this vulnerability to cause a denial… archsusedebian
CVE-2018-14463 medium 5.5 The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167. suserockylinuxdebian
CVE-2018-19532 medium 5.5 A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It all… archsusedebian
CVE-2018-16866 medium 5.5 An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Version… archsusedebian
CVE-2018-0739 medium 5.5 Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of … archsusedebian
CVE-2018-1122 medium 5.5 procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege esca… archsusedebian
CVE-2018-5730 medium 5.5 MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerd… archsusedebian
CVE-2018-14882 medium 5.5 The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c. suserockylinuxdebian
CVE-2018-14469 medium 5.5 The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print(). suserockylinuxdebian
CVE-2018-5296 medium 5.5 In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PdfParser::ReadXRefSubsection function (base/PdfParser.cpp). Remote attackers could leverage this vulnerability to cause a denial-of… archsusedebian
CVE-2018-20797 medium 5.5 An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp when called from PoDoFo::PdfPredictorDecoder::PdfPr… archsusedebian
CVE-2018-7727 medium 5.5 An issue was discovered in ZZIPlib 0.13.68. There is a memory leak triggered in the function zzip_mem_disk_new in memdisk.c, which will lead to a denial of service attack. archsusedebian
CVE-2018-12543 medium 5.5 In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert is triggered that … archdebian
CVE-2018-1303 medium 5.5 multiple issues in apache debianarchsuse
CVE-2018-20103 medium 5.5 An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a lon… archsusedebian
CVE-2018-20102 medium 5.5 An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 … archsusedebian
CVE-2018-1301 medium 5.5 multiple issues in apache debianarchsuse
CVE-2018-1000035 medium 5.5 A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve co… archsusedebian
CVE-2018-1126 medium 5.5 procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124. archsusedebian
CVE-2018-14467 medium 5.5 The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP). suserockylinuxdebian
CVE-2018-14466 medium 5.5 The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert(). suserockylinuxdebian
CVE-2018-16227 medium 5.5 The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield. suserockylinuxdebian
CVE-2018-14461 medium 5.5 The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print(). suserockylinuxdebian
CVE-2018-12982 medium 5.5 Invalid memory read in the PoDoFo::PdfVariant::DelayedLoad() function in PdfVariant.h in PoDoFo 0.9.6-rc1 allows remote attackers to have denial-of-service impact via a crafted file. archsusedebian
CVE-2018-6541 medium 5.5 In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address (when handling disk64_trailer local entries) in __zzip_fetch_disk_trailer (zzip/zip.c). Remote attackers could lever… archsusedebian
CVE-2018-10105 medium 5.5 tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2). suserockylinuxdebian
CVE-2018-14464 medium 5.5 The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs(). suserockylinuxdebian
CVE-2018-25306 medium 5.5 5.5 29d ago PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files during merge operations. Attackers can trigger a segmen… ubuntu
CVE-2018-25267 medium 5.5 5.5 1mo ago UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwrite SEH and SE handler records. Attacker…
CVE-2018-17828 medium 5.5 7mo ago Moderate: zziplib security update redhatsuserockylinuxdebian
CVE-2018-15209 medium 5.5 2y ago Moderate: libtiff security update suserockylinuxdebian
CVE-2018-18624 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update susegolang
CVE-2018-7260 medium 5.5 4y ago Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. archdebianphp
CVE-2018-13258 medium 5.5 4y ago Mediawiki tarball is missing .htaccess files archdebianphp
CVE-2018-1000120 medium 5.5 4y ago curl FTP path confusion leads to NIL byte out of bounds write archsusedebiannuget
CVE-2018-1999043 medium 5.5 4y ago Missing Release of Resource after Effective Lifetime in Jenkins archjava
CVE-2018-0503 medium 5.5 4y ago Mediawiki Improper Privilege Management archdebianphp
CVE-2018-0505 medium 5.5 4y ago Mediawiki BotPassword can bypass CentralAuth's account lock archdebianphp
CVE-2018-14773 medium 5.5 4y ago An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises … archdebianphp
CVE-2018-14040 medium 5.5 4y ago Bootstrap vulnerable to Cross-Site Scripting (XSS) rockylinuxdebianrubynpm+3
CVE-2018-20845 medium 5.5 5y ago Moderate: openjpeg2 security update suserockylinuxdebian
CVE-2018-5727 medium 5.5 5y ago Moderate: openjpeg2 security update suserockylinuxdebian
CVE-2018-20847 medium 5.5 5y ago Moderate: openjpeg2 security update suserockylinuxdebian
CVE-2018-5785 medium 5.5 5y ago Moderate: openjpeg2 security update suserockylinuxdebian
CVE-2018-25013 medium 5.5 5y ago Moderate: libwebp security update suserockylinuxdebian
CVE-2018-25012 medium 5.5 5y ago Moderate: libwebp security update suserockylinuxdebian
CVE-2018-25010 medium 5.5 5y ago Moderate: libwebp security update suserockylinuxdebian
CVE-2018-25009 medium 5.5 5y ago Moderate: libwebp security update suserockylinuxdebian
CVE-2018-25014 medium 5.5 5y ago Moderate: libwebp security update suserockylinuxdebian
CVE-2018-21247 medium 5.5 5y ago Moderate: libvncserver security update suserockylinuxdebian
CVE-2018-17199 medium 5.5 5y ago Moderate: httpd:2.4 security, bug fix, and enhancement update debianarchsuserockylinux
CVE-2018-20843 medium 5.5 6y ago In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enoug… susedebianrockylinux
CVE-2018-17189 medium 5.5 6y ago Moderate: httpd:2.4 security, bug fix, and enhancement update debianarchsuserockylinux
CVE-2018-11782 medium 5.5 6y ago Moderate: subversion:1.10 security update archsuserockylinuxdebian
CVE-2018-21035 medium 5.5 6y ago Moderate: qt5-qtbase and qt5-qtwebsockets security and bug fix update suserockylinuxdebian
CVE-2018-14553 medium 5.5 6y ago Moderate: gd security update susedebianrockylinux
CVE-2018-1000858 medium 5.5 6y ago Moderate: gnupg2 security, bug fix, and enhancement update susedebianrockylinux
CVE-2018-20337 medium 5.5 6y ago Moderate: GNOME security, bug fix, and enhancement update susedebianrockylinux
CVE-2018-11685 medium 5.5 6y ago Moderate: liblouis security and bug fix update susedebianrockylinux
CVE-2018-11577 medium 5.5 6y ago Moderate: liblouis security and bug fix update susedebianrockylinux
CVE-2018-11684 medium 5.5 6y ago Moderate: liblouis security and bug fix update susedebianrockylinux
CVE-2018-12085 medium 5.5 6y ago Moderate: liblouis security and bug fix update susedebianrockylinux
CVE-2018-19872 medium 5.5 6y ago Moderate: qt5 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2018-19871 medium 5.5 6y ago Moderate: qt5 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2018-19869 medium 5.5 6y ago Moderate: qt5 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2018-19662 medium 5.5 6y ago Moderate: libsndfile security update archdebianrockylinux
CVE-2018-13139 medium 5.5 6y ago Moderate: libsndfile security update archsusedebianrockylinux
CVE-2018-20783 medium 5.5 6y ago Moderate: php:7.2 security, bug fix, and enhancement update suserockylinux
CVE-2018-20852 medium 5.5 6y ago Moderate: python27:2.7 security, bug fix, and enhancement update suserockylinuxdebian
CVE-2018-9303 medium 5.5 6y ago Moderate: exiv2 security, bug fix, and enhancement update susedebianrockylinuxalmalinux
CVE-2018-10772 medium 5.5 6y ago Moderate: exiv2 security, bug fix, and enhancement update susedebianrockylinux
CVE-2018-14338 medium 5.5 6y ago Moderate: exiv2 security, bug fix, and enhancement update debianrockylinux
CVE-2018-19607 medium 5.5 6y ago Moderate: exiv2 security, bug fix, and enhancement update susedebianrockylinux