CVEs from 2018

2,887 normalized CVEs published or assigned in this year.

Total
2,887
critical
critical 238
high
high 329
medium
medium 259
low
low 39
% Critical
8.2%
% with KEV
3.1%
% with exploit
9.0%

Top products

  • core_i7 379
  • core_i5 375
  • core_i3 242
  • xeon_e5 82
  • xeon_e7 62
  • xeon_e3 58
  • xeon_gold 33
  • atom_z 30
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2018-25012 medium 5.5 5y ago RHSA-2021:4231: libwebp security update (Moderate)
CVE-2018-25009 medium 5.5 5y ago RHSA-2021:4231: libwebp security update (Moderate)
CVE-2018-25010 medium 5.5 5y ago RHSA-2021:4231: libwebp security update (Moderate)
CVE-2018-21247 medium 5.5 5y ago An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.
CVE-2018-17199 medium 5.5 5y ago In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessio…
CVE-2018-16300 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-11805 medium 5.5 6y ago RHSA-2020:4625: spamassassin security update (Moderate)
CVE-2018-16452 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-16451 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-16230 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14461 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14467 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14468 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14464 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14466 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14465 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14462 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-16229 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-16228 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-10105 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14880 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14879 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14881 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14463 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-10103 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14469 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14470 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-16227 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-14882 medium 5.5 6y ago RHSA-2020:4760: tcpdump security, bug fix, and enhancement update (Moderate)
CVE-2018-20843 medium 5.5 6y ago RHSA-2020:4846: mingw-expat security update (Moderate)
CVE-2018-17189 medium 5.5 6y ago In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up th…
CVE-2018-11782 medium 5.5 6y ago RHSA-2020:4712: subversion:1.10 security update (Moderate)
CVE-2018-21035 medium 5.5 6y ago RHSA-2020:4690: qt5-qtbase and qt5-qtwebsockets security and bug fix update (Moderate)
CVE-2018-14553 medium 5.5 6y ago RHSA-2020:4659: gd security update (Moderate)
CVE-2018-1000858 medium 5.5 6y ago RHSA-2020:4490: gnupg2 security, bug fix, and enhancement update (Moderate)
CVE-2018-20337 medium 5.5 6y ago RHSA-2020:1766: GNOME security, bug fix, and enhancement update (Moderate)
CVE-2018-11577 medium 5.5 6y ago Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c.
CVE-2018-11685 medium 5.5 6y ago Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c.
CVE-2018-11684 medium 5.5 6y ago Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTable.c.
CVE-2018-12085 medium 5.5 6y ago Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.
CVE-2018-19871 medium 5.5 6y ago RHSA-2020:1665: qt5 security, bug fix, and enhancement update (Moderate)
CVE-2018-19869 medium 5.5 6y ago RHSA-2020:1665: qt5 security, bug fix, and enhancement update (Moderate)
CVE-2018-19872 medium 5.5 6y ago RHSA-2020:1665: qt5 security, bug fix, and enhancement update (Moderate)
CVE-2018-19662 medium 5.5 6y ago RHSA-2020:1636: libsndfile security update (Moderate)
CVE-2018-13139 medium 5.5 6y ago RHSA-2020:1636: libsndfile security update (Moderate)
CVE-2018-20783 medium 5.5 6y ago RHSA-2020:1624: php:7.2 security, bug fix, and enhancement update (Moderate)
CVE-2018-20852 medium 5.5 6y ago RHSA-2020:1764: python3 security and bug fix update (Moderate)
CVE-2018-4868 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-9303 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-9305 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-9306 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-9304 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-17581 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-17230 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-11037 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-17282 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-17229 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-14338 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-10772 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-19107 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-19607 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-19535 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-19108 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-18915 medium 5.5 6y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-9251 medium 5.5 6y ago RHSA-2020:1827: libxml2 security update (Moderate)
CVE-2018-15587 medium 5.5 6y ago RHSA-2020:1600: evolution security and bug fix update (Moderate)
CVE-2018-14498 medium 5.5 7y ago RHSA-2019:3705: libjpeg-turbo security update (Moderate)
CVE-2018-19870 medium 5.5 7y ago RHSA-2019:3390: qt5-qtbase security and bug fix update (Moderate)
CVE-2018-15518 medium 5.5 7y ago RHSA-2019:3390: qt5-qtbase security and bug fix update (Moderate)
CVE-2018-19873 medium 5.5 7y ago RHSA-2019:3390: qt5-qtbase security and bug fix update (Moderate)
CVE-2018-16890 medium 5.5 7y ago libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does…
CVE-2018-20685 medium 5.5 7y ago In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the tar…
CVE-2018-1000878 medium 5.5 7y ago RHSA-2019:3698: libarchive security and bug fix update (Moderate)
CVE-2018-12900 medium 5.5 7y ago RHSA-2019:3419: libtiff security update (Moderate)
CVE-2018-1000877 medium 5.5 7y ago RHSA-2019:3698: libarchive security and bug fix update (Moderate)
CVE-2018-12121 medium 5.5 7y ago RHSA-2019:3497: http-parser security and bug fix update (Moderate)
CVE-2018-12181 medium 5.5 7y ago RHSA-2019:3338: edk2 security, bug fix, and enhancement update (Moderate)
CVE-2018-20534 medium 5.5 7y ago There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects t…
CVE-2018-20483 medium 5.5 7y ago RHSA-2019:3701: curl security and bug fix update (Moderate)
CVE-2018-20551 medium 5.5 7y ago A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Anno…
CVE-2018-18897 medium 5.5 7y ago An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.
CVE-2018-20662 medium 5.5 7y ago In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by craft…
CVE-2018-20650 medium 5.5 7y ago A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec clas…
CVE-2018-20481 medium 5.5 7y ago XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when…
CVE-2018-18508 medium 5.5 7y ago In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.
CVE-2018-19800 medium 5.5 7y ago aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo.
CVE-2018-19802 medium 5.5 7y ago aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference.
CVE-2018-19801 medium 5.5 7y ago aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in new_aubio_filterbank via invalid n_filters.
CVE-2018-20677 medium 5.5 8y ago RHSA-2020:4670: idm:DL1 and idm:client security, bug fix, and enhancement update (Moderate)
CVE-2018-20676 medium 5.5 8y ago RHSA-2020:4670: idm:DL1 and idm:client security, bug fix, and enhancement update (Moderate)
CVE-2018-7536 medium 5.5 8y ago An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastroph…
CVE-2018-7537 medium 5.5 8y ago An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they w…
CVE-2018-20060 medium 5.5 8y ago RHSA-2020:1916: python-pip security update (Moderate)
CVE-2018-20097 medium 5.5 8y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-20099 medium 5.5 8y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-20098 medium 5.5 8y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-20096 medium 5.5 8y ago RHSA-2020:1577: exiv2 security, bug fix, and enhancement update (Moderate)
CVE-2018-19352 medium 5.5 8y ago Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
CVE-2018-19351 medium 5.5 8y ago Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can e…
CVE-2018-18074 medium 5.5 8y ago RHSA-2020:1916: python-pip security update (Moderate)