CVEs from 2018
Total
3,288
critical
critical 226
high
high 266
medium
medium 224
low
low 32
% Critical
6.9%
% with KEV
2.7%
% with exploit
2.8%
Top vendors
- frappe 4
- redhat 2
- magix 1
- mybb 1
- gitbucket 1
- qemu 1
- dragonexpert 1
- kingsoftstore 1
Top products
- erpnext 4
- terminal_services_manager 1
- ultraiso 1
- dolibarr_erp\/crm 1
- gitbucket 1
- pdfunite 1
- qemu 1
- virtualization_manager 1
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2018-1312 | medium | — | 5.5 | — | multiple issues in apache | |
| CVE-2018-1333 | medium | — | 5.5 | — | denial of service in apache | |
| CVE-2018-1302 | medium | — | 5.5 | — | multiple issues in apache | |
| CVE-2018-10105 | medium | — | 5.5 | — | tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2). | |
| CVE-2018-11255 | medium | — | 5.5 | — | An issue was discovered in PoDoFo 0.9.5. The function PdfPage::GetPageNumber() in PdfPage.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and applic… | |
| CVE-2018-18310 | medium | — | 5.5 | — | An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (applicatio… | |
| CVE-2018-14879 | medium | — | 5.5 | — | The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file(). | |
| CVE-2018-5738 | medium | — | 5.5 | — | Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND names… | |
| CVE-2018-12606 | medium | — | 5.5 | — | multiple issues in gitlab | |
| CVE-2018-12607 | medium | — | 5.5 | — | multiple issues in gitlab | |
| CVE-2018-11805 | medium | — | 5.5 | — | In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In additio… | |
| CVE-2018-16866 | medium | — | 5.5 | — | multiple issues in systemd | |
| CVE-2018-6954 | medium | — | 5.5 | — | multiple issues in systemd | |
| CVE-2018-16452 | medium | — | 5.5 | — | The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion. | |
| CVE-2018-14464 | medium | — | 5.5 | — | The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs(). | |
| CVE-2018-20103 | medium | — | 5.5 | — | An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a lon… | |
| CVE-2018-6459 | medium | — | 5.5 | — | The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that… | |
| CVE-2018-16451 | medium | — | 5.5 | — | The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN. | |
| CVE-2018-14468 | medium | — | 5.5 | — | The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print(). | |
| CVE-2018-19532 | medium | — | 5.5 | — | A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It all… | |
| CVE-2018-5783 | medium | — | 5.5 | — | In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecObjects.h). Remote attackers could leverage this vulnerability to cause a denial… | |
| CVE-2018-11254 | medium | — | 5.5 | — | An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree::GetPageNode() function of PdfPagesTree.cpp. Remote attackers could leverage this vulnerability to cause a… | |
| CVE-2018-11256 | medium | — | 5.5 | — | An issue was discovered in PoDoFo 0.9.5. The function PdfDocument::Append() in PdfDocument.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and appli… | |
| CVE-2018-14469 | medium | — | 5.5 | — | The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print(). | |
| CVE-2018-9251 | medium | — | 5.5 | — | The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERR… | |
| CVE-2018-14463 | medium | — | 5.5 | — | The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167. | |
| CVE-2018-16300 | medium | — | 5.5 | — | The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion. | |
| CVE-2018-5295 | medium | — | 5.5 | — | In PoDoFo 0.9.5, there is an integer overflow in the PdfXRefStreamParserObject::ParseStream function (base/PdfXRefStreamParserObject.cpp). Remote attackers could leverage this vulnerability to cause … | |
| CVE-2018-5309 | medium | — | 5.5 | — | In PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function (base/PdfObjectStreamParserObject.cpp). Remote attackers could leverage this vulnerabi… | |
| CVE-2018-6352 | medium | — | 5.5 | — | In PoDoFo 0.9.5, there is an Excessive Iteration in the PdfParser::ReadObjectsInternal function of base/PdfParser.cpp. Remote attackers could leverage this vulnerability to cause a denial of service … | |
| CVE-2018-6541 | medium | — | 5.5 | — | In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address (when handling disk64_trailer local entries) in __zzip_fetch_disk_trailer (zzip/zip.c). Remote attackers could lever… | |
| CVE-2018-1000035 | medium | — | 5.5 | — | A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve co… | |
| CVE-2018-1123 | medium | — | 5.5 | — | procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at the end of the overflowed buffer, ensuring that the … | |
| CVE-2018-1126 | medium | — | 5.5 | — | procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124. | |
| CVE-2018-18520 | medium | — | 5.5 | — | An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes… | |
| CVE-2018-7549 | medium | — | 5.5 | — | In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p. | |
| CVE-2018-7725 | medium | — | 5.5 | — | An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability causes an application crash, which leads to denial … | |
| CVE-2018-20751 | medium | — | 5.5 | — | An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject(… | |
| CVE-2018-5308 | medium | — | 5.5 | — | PoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStream.cpp). Remote attackers could leverage this vulnerability to cause a denial-… | |
| CVE-2018-8001 | medium | — | 5.5 | — | In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly… | |
| CVE-2018-16229 | medium | — | 5.5 | — | The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option(). | |
| CVE-2018-15473 | medium | — | 5.5 | — | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, re… | |
| CVE-2018-14465 | medium | — | 5.5 | — | The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print(). | |
| CVE-2018-14462 | medium | — | 5.5 | — | The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print(). | |
| CVE-2018-14880 | medium | — | 5.5 | — | The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr(). | |
| CVE-2018-14470 | medium | — | 5.5 | — | The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2(). | |
| CVE-2018-14644 | medium | — | 5.5 | — | An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DN… | |
| CVE-2018-12543 | medium | — | 5.5 | — | In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert is triggered that … | |
| CVE-2018-1125 | medium | — | 5.5 | — | procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is comp… | |
| CVE-2018-16228 | medium | — | 5.5 | — | The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix(). | |
| CVE-2018-12983 | medium | — | 5.5 | — | A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be leveraged by remote attackers to cause a denial-of-service via … | |
| CVE-2018-16855 | medium | — | 5.5 | — | An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds memory read while computing the hash of the query for a pack… | |
| CVE-2018-19661 | medium | — | 5.5 | — | An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of service. | |
| CVE-2018-17478 | medium | — | 5.5 | — | information disclosure in chromium | |
| CVE-2018-1124 | medium | — | 5.5 | — | procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can creat… | |
| CVE-2018-25306 | medium | 5.5 | 5.5 | 29d ago | PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files during merge operations. Attackers can trigger a segmen… | |
| CVE-2018-25267 | medium | 5.5 | 5.5 | 1mo ago | UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwrite SEH and SE handler records. Attacker… | |
| CVE-2018-17828 | medium | — | 5.5 | 7mo ago | Moderate: zziplib security update | |
| CVE-2018-15209 | medium | — | 5.5 | 2y ago | Moderate: libtiff security update | |
| CVE-2018-18624 | medium | — | 5.5 | 4y ago | Moderate: grafana security, bug fix, and enhancement update | |
| CVE-2018-7260 | medium | — | 5.5 | 4y ago | Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| CVE-2018-13258 | medium | — | 5.5 | 4y ago | Mediawiki tarball is missing .htaccess files | |
| CVE-2018-1000120 | medium | — | 5.5 | 4y ago | curl FTP path confusion leads to NIL byte out of bounds write | |
| CVE-2018-1999043 | medium | — | 5.5 | 4y ago | Missing Release of Resource after Effective Lifetime in Jenkins | |
| CVE-2018-0503 | medium | — | 5.5 | 4y ago | Mediawiki Improper Privilege Management | |
| CVE-2018-0505 | medium | — | 5.5 | 4y ago | Mediawiki BotPassword can bypass CentralAuth's account lock | |
| CVE-2018-14773 | medium | — | 5.5 | 4y ago | An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises … | |
| CVE-2018-14040 | medium | — | 5.5 | 4y ago | Bootstrap vulnerable to Cross-Site Scripting (XSS) | |
| CVE-2018-5785 | medium | — | 5.5 | 5y ago | Moderate: openjpeg2 security update | |
| CVE-2018-5727 | medium | — | 5.5 | 5y ago | Moderate: openjpeg2 security update | |
| CVE-2018-20847 | medium | — | 5.5 | 5y ago | Moderate: openjpeg2 security update | |
| CVE-2018-20845 | medium | — | 5.5 | 5y ago | Moderate: openjpeg2 security update | |
| CVE-2018-25009 | medium | — | 5.5 | 5y ago | Moderate: libwebp security update | |
| CVE-2018-25014 | medium | — | 5.5 | 5y ago | Moderate: libwebp security update | |
| CVE-2018-25010 | medium | — | 5.5 | 5y ago | Moderate: libwebp security update | |
| CVE-2018-25013 | medium | — | 5.5 | 5y ago | Moderate: libwebp security update | |
| CVE-2018-25012 | medium | — | 5.5 | 5y ago | Moderate: libwebp security update | |
| CVE-2018-21247 | medium | — | 5.5 | 5y ago | Moderate: libvncserver security update | |
| CVE-2018-17199 | medium | — | 5.5 | 5y ago | Moderate: httpd:2.4 security, bug fix, and enhancement update | |
| CVE-2018-20843 | medium | — | 5.5 | 6y ago | In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enoug… | |
| CVE-2018-17189 | medium | — | 5.5 | 6y ago | Moderate: httpd:2.4 security, bug fix, and enhancement update | |
| CVE-2018-11782 | medium | — | 5.5 | 6y ago | Moderate: subversion:1.10 security update | |
| CVE-2018-21035 | medium | — | 5.5 | 6y ago | Moderate: qt5-qtbase and qt5-qtwebsockets security and bug fix update | |
| CVE-2018-14553 | medium | — | 5.5 | 6y ago | Moderate: gd security update | |
| CVE-2018-1000858 | medium | — | 5.5 | 6y ago | Moderate: gnupg2 security, bug fix, and enhancement update | |
| CVE-2018-20337 | medium | — | 5.5 | 6y ago | Moderate: GNOME security, bug fix, and enhancement update | |
| CVE-2018-11684 | medium | — | 5.5 | 6y ago | Moderate: liblouis security and bug fix update | |
| CVE-2018-12085 | medium | — | 5.5 | 6y ago | Moderate: liblouis security and bug fix update | |
| CVE-2018-11685 | medium | — | 5.5 | 6y ago | Moderate: liblouis security and bug fix update | |
| CVE-2018-11577 | medium | — | 5.5 | 6y ago | Moderate: liblouis security and bug fix update | |
| CVE-2018-19872 | medium | — | 5.5 | 6y ago | Moderate: qt5 security, bug fix, and enhancement update | |
| CVE-2018-19869 | medium | — | 5.5 | 6y ago | Moderate: qt5 security, bug fix, and enhancement update | |
| CVE-2018-19871 | medium | — | 5.5 | 6y ago | Moderate: qt5 security, bug fix, and enhancement update | |
| CVE-2018-13139 | medium | — | 5.5 | 6y ago | Moderate: libsndfile security update | |
| CVE-2018-19662 | medium | — | 5.5 | 6y ago | Moderate: libsndfile security update | |
| CVE-2018-20783 | medium | — | 5.5 | 6y ago | Moderate: php:7.2 security, bug fix, and enhancement update | |
| CVE-2018-20852 | medium | — | 5.5 | 6y ago | Moderate: python27:2.7 security, bug fix, and enhancement update | |
| CVE-2018-9305 | medium | — | 5.5 | 6y ago | Moderate: exiv2 security, bug fix, and enhancement update | |
| CVE-2018-17282 | medium | — | 5.5 | 6y ago | Moderate: exiv2 security, bug fix, and enhancement update | |
| CVE-2018-18915 | medium | — | 5.5 | 6y ago | Moderate: exiv2 security, bug fix, and enhancement update |