CVEs from 2018
Total
2,860
critical
critical 238
high
high 331
medium
medium 263
low
low 39
% Critical
8.3%
% with KEV
3.1%
% with exploit
9.1%
Top vendors
- intel 1,561
- schneider-electric 43
- siemens 42
- rockwellautomation 16
- echelon 15
- redhat 12
- oracle 9
- arm 9
Top products
- core_i7 379
- core_i5 375
- core_i3 242
- xeon_e5 82
- xeon_e7 62
- xeon_e3 58
- xeon_gold 33
- atom_z 30
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-7452 | low | — | 2.5 | — | A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | |||
| CVE-2018-6942 | low | — | 2.5 | — | An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file. | |||
| CVE-2018-20225 | low | — | 2.5 | — | arbitrary code execution in python-pip | |||
| CVE-2018-7455 | low | — | 2.5 | — | An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | |||
| CVE-2018-20482 | low | — | 2.5 | — | GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c)… | |||
| CVE-2018-7175 | low | — | 2.5 | — | An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components. | |||
| CVE-2018-0732 | low | — | 2.5 | — | During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long pe… | |||
| CVE-2018-5388 | low | — | 2.5 | — | In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket. | |||
| CVE-2018-0502 | low | — | 2.5 | — | insufficient validation in zsh | |||
| CVE-2018-13259 | low | — | 2.5 | — | insufficient validation in zsh | |||
| CVE-2018-8956 | low | — | 2.5 | — | ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packet… | |||
| CVE-2018-7174 | low | — | 2.5 | — | An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams. | |||
| CVE-2018-9055 | low | — | 2.5 | — | denial of service in jasper | |||
| CVE-2018-9234 | low | — | 2.5 | — | GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with acce… | |||
| CVE-2018-7453 | low | — | 2.5 | — | Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml. | |||
| CVE-2018-12699 | low | — | 2.5 | 2y ago | RHSA-2024:9689: binutils security update (Low) | |||
| CVE-2018-20673 | low | — | 2.5 | 5y ago | RHSA-2021:4386: gcc security and bug fix update (Low) | |||
| CVE-2018-10896 | low | — | 2.5 | 6y ago | RHSA-2020:3050: cloud-init security, bug fix, and enhancement update (Low) | |||
| CVE-2018-7263 | low | — | 2.5 | 6y ago | RHSA-2020:1631: GStreamer, libmad, and SDL security, bug fix, and enhancement update (Low) | |||
| CVE-2018-19840 | low | — | 2.5 | 6y ago | RHSA-2020:1581: wavpack security update (Low) | |||
| CVE-2018-19841 | low | — | 2.5 | 6y ago | RHSA-2020:1581: wavpack security update (Low) | |||
| CVE-2018-10910 | low | — | 2.5 | 6y ago | RHSA-2020:1912: bluez security update (Low) | |||
| CVE-2018-19519 | low | — | 2.5 | 6y ago | RHSA-2020:1604: tcpdump security update (Low) | |||
| CVE-2018-10392 | low | — | 2.5 | 7y ago | RHSA-2019:3703: libvorbis security update (Low) | |||
| CVE-2018-10393 | low | — | 2.5 | 7y ago | RHSA-2019:3703: libvorbis security update (Low) | |||
| CVE-2018-18751 | low | — | 2.5 | 7y ago | RHSA-2019:3643: gettext security update (Low) | |||
| CVE-2018-6616 | low | — | 2.5 | 7y ago | RHBA-2019:3408: openjpeg2 bug fix and enhancement update (Low) | |||
| CVE-2018-16838 | low | — | 2.5 | 7y ago | RHSA-2019:3651: sssd security, bug fix, and enhancement update (Low) | |||
| CVE-2018-10932 | low | — | 2.5 | 7y ago | RHSA-2019:3673: lldpad security and bug fix update (Low) | |||
| CVE-2018-20657 | low | — | 2.5 | 7y ago | RHSA-2019:3352: gdb security, bug fix, and enhancement update (Low) | |||
| CVE-2018-0735 | low | — | 2.5 | 7y ago | RHSA-2019:3700: openssl security, bug fix, and enhancement update (Low) | |||
| CVE-2018-0734 | low | — | 2.5 | 7y ago | RHSA-2019:3700: openssl security, bug fix, and enhancement update (Low) | |||
| CVE-2018-5745 | low | — | 2.5 | 7y ago | RHSA-2019:3552: bind security and bug fix update (Low) |