CVEs from 2018

3,288 normalized CVEs published or assigned in this year.

Total
3,288
critical
critical 226
high
high 266
medium
medium 224
low
low 32
% Critical
6.9%
% with KEV
2.7%
% with exploit
2.8%

Top products

  • erpnext 4
  • terminal_services_manager 1
  • ultraiso 1
  • dolibarr_erp\/crm 1
  • gitbucket 1
  • pdfunite 1
  • qemu 1
  • virtualization_manager 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2018-17480 critical 10.0 4y ago multiple issues in chromium archdebian
CVE-2018-17463 critical 10.0 4y ago multiple issues in chromium arch
CVE-2018-7602 critical 10.0 8y ago A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. archphp
CVE-2018-7600 critical 10.0 8y ago Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise. archphp
CVE-2018-25357 critical 9.8 9.8 5d ago Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers ca…
CVE-2018-25350 critical 9.8 9.8 5d ago userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. At…
CVE-2018-25335 critical 9.8 9.8 11d ago WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint.…
CVE-2018-25332 critical 9.8 9.8 11d ago GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file uploa…
CVE-2018-25320 critical 9.8 9.8 11d ago ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can …
CVE-2018-25318 critical 9.8 9.8 29d ago Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers ca…
CVE-2018-25317 critical 9.8 9.8 29d ago Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient se…
CVE-2018-25316 critical 9.8 9.8 29d ago Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send…
CVE-2018-25272 critical 9.8 9.8 1mo ago ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can connect to …
CVE-2018-18340 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18640 critical 9.5 multiple issues in gitlab arch
CVE-2018-5127 critical 9.5 A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR… archsusedebian
CVE-2018-19876 critical 9.5 cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): invalid… archdebian
CVE-2018-6088 critical 9.5 multiple issues in chromium arch
CVE-2018-6095 critical 9.5 multiple issues in chromium arch
CVE-2018-11358 critical 9.5 In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was addressed in epan/dissectors/packet-q931.c by avoiding a use-after-free after a malformed packet pre… archsusedebian
CVE-2018-19625 critical 9.5 In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_composite.c by preventing a heap-based buffer over-read. archsusedebian
CVE-2018-12386 critical 9.5 A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process whe… archsusedebian
CVE-2018-12364 critical 9.5 NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious sit… archsusedebian
CVE-2018-6091 critical 9.5 multiple issues in chromium arch
CVE-2018-6096 critical 9.5 multiple issues in chromium arch
CVE-2018-6094 critical 9.5 multiple issues in chromium arch
CVE-2018-12374 critical 9.5 Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9. archsusedebian
CVE-2018-5152 critical 9.5 WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For exa… archdebian
CVE-2018-5764 critical 9.5 The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection me… archsusedebian
CVE-2018-12363 critical 9.5 A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node being freed but the node still having a… archsusedebian
CVE-2018-18336 critical 9.5 multiple issues in chromium archdebian
CVE-2018-11360 critical 9.5 In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epan/dissectors/packet-gsm_a_dtap.c by fixing an off-by-one error that caused a bu… archsusedebian
CVE-2018-17481 critical 9.5 multiple issues in chromium archdebian
CVE-2018-12397 critical 9.5 A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to … archsusedebian
CVE-2018-17464 critical 9.5 multiple issues in chromium arch
CVE-2018-5172 critical 9.5 The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site… archdebian
CVE-2018-6100 critical 9.5 multiple issues in chromium arch
CVE-2018-18505 critical 9.5 An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This … archsusedebian
CVE-2018-12362 critical 9.5 An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploitable crash. This vulnerability affects … archsusedebian
CVE-2018-12373 critical 9.5 dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9. archsusedebian
CVE-2018-6098 critical 9.5 multiple issues in chromium arch
CVE-2018-6118 critical 9.5 arbitrary code execution in chromium arch
CVE-2018-6115 critical 9.5 multiple issues in chromium arch
CVE-2018-18493 critical 9.5 A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in … archsusedebian
CVE-2018-10933 critical 9.5 A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unautho… archsusedebian
CVE-2018-6101 critical 9.5 multiple issues in chromium arch
CVE-2018-12395 critical 9.5 By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are o… archsusedebian
CVE-2018-5711 critical 9.5 gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an in… archsusedebian
CVE-2018-5150 critical 9.5 Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of the… archsusedebian
CVE-2018-6087 critical 9.5 multiple issues in chromium arch
CVE-2018-11361 critical 9.5 In Wireshark 2.6.0, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/dot11decrypt.c by avoiding a buffer overflow during FTE processing in Dot11DecryptTDLSDeriveKey. archsusedebian
CVE-2018-19622 critical 9.5 In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse.c by preventing length overflows. archsusedebian
CVE-2018-12371 critical 9.5 An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting i… archsusedebian
CVE-2018-12365 critical 9.5 A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private l… archsusedebian
CVE-2018-6109 critical 9.5 multiple issues in chromium arch
CVE-2018-5183 critical 9.5 Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerabil… archdebian
CVE-2018-11357 critical 9.5 In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. This was addressed in epan/tvbuff.c by rejecting negative lengths. archsusedebian
CVE-2018-5187 critical 9.5 Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to ru… archsusedebian
CVE-2018-18344 critical 9.5 multiple issues in chromium archdebian
CVE-2018-17477 critical 9.5 multiple issues in chromium arch
CVE-2018-6110 critical 9.5 multiple issues in chromium arch
CVE-2018-12405 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enoug… archsusedebian
CVE-2018-6112 critical 9.5 multiple issues in chromium arch
CVE-2018-6105 critical 9.5 multiple issues in chromium arch
CVE-2018-12367 critical 9.5 In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTimi… archsusedebian
CVE-2018-12403 critical 9.5 If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnerability affects Firefox < 63. archsusedebian
CVE-2018-12385 critical 9.5 A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination w… archsusedebian
CVE-2018-12378 critical 9.5 A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploita… archsusedebian
CVE-2018-17474 critical 9.5 multiple issues in chromium arch
CVE-2018-6117 critical 9.5 multiple issues in chromium arch
CVE-2018-18358 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18502 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of… archsusedebian
CVE-2018-17467 critical 9.5 multiple issues in chromium arch
CVE-2018-6104 critical 9.5 multiple issues in chromium arch
CVE-2018-12377 critical 9.5 A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exp… archsusedebian
CVE-2018-5173 critical 9.5 The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially exe… archdebian
CVE-2018-12399 critical 9.5 When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approvin… archdebian
CVE-2018-5184 critical 9.5 Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. archdebian
CVE-2018-18355 critical 9.5 multiple issues in chromium archdebian
CVE-2018-5144 critical 9.5 An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7. archsusedebian
CVE-2018-18335 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2018-18649 critical 9.5 multiple issues in gitlab arch
CVE-2018-18345 critical 9.5 multiple issues in chromium archdebian
CVE-2018-6097 critical 9.5 multiple issues in chromium arch
CVE-2018-18646 critical 9.5 multiple issues in gitlab arch
CVE-2018-6103 critical 9.5 multiple issues in chromium arch
CVE-2018-6108 critical 9.5 multiple issues in chromium arch
CVE-2018-6107 critical 9.5 multiple issues in chromium arch
CVE-2018-11354 critical 9.5 In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed in epan/dissectors/packet-ieee1905.c by making a certain correction to string handling. archsusedebian
CVE-2018-12369 critical 9.5 WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects… archsusedebian
CVE-2018-6102 critical 9.5 multiple issues in chromium arch
CVE-2018-1000300 critical 9.5 curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based me… archdebian
CVE-2018-18648 critical 9.5 multiple issues in gitlab arch
CVE-2018-18354 critical 9.5 multiple issues in chromium archdebian
CVE-2018-5168 critical 9.5 Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without… archdebian
CVE-2018-10528 critical 9.5 An issue was discovered in LibRaw 0.18.9. There is a stack-based buffer overflow in the utf2char function in libraw_cxx.cpp. archdebian
CVE-2018-5156 critical 9.5 A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being cast to the wrong type causing a potent… archsusedebian
CVE-2018-18506 critical 9.5 When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to … archsusedebian
CVE-2018-18501 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enoug… archsusedebian
CVE-2018-19624 critical 9.5 In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/packet-pvfs2.c by preventing a NULL pointer dereference. archsusedebian