16,510 vulnerabilities published in 2018
There is a heap-based buffer over-read at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 tha
There is a NULL pointer dereference at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that w
There is a Segmentation fault triggered by illegal address access at liblas::SpatialReference::GetGTIF() (spatialreferen
There is memory leak at liblas::Open (liblas/liblas.hpp) in libLAS 1.8.1.
There is an attempted excessive memory allocation at libxsmm_sparse_csc_reader in generator_spgemm_csc_reader.c in LIBXS
There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construct
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
The Scanner::EnsureTokensInQueue function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial
The SingleDocParser::HandleFlowMap function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denia
JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the
lib/support/unicodeconv/unicodeconv.c in libotfcc.a in otfcc v0.10.3-alpha has a buffer over-read.
A heap-based buffer over-read was discovered in decompileJUMP function in util/decompile.c of libming v0.4.8. A crafted
Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, ve
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
Vulnerability in the Oracle Argus Safety component of Oracle Health Sciences Applications (subcomponent: Case Selection)
Vulnerability in the Oracle Retail Merchandising System component of Oracle Retail Applications (subcomponent: Cross Pil
Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAf
When the F5 BIG-IP 12.1.0-12.1.1, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 system is configured with a wildcard IPSec tun
Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base).
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not prope
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo execut
A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRep
An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) val
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An atta
For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart
Vulnerability in the MICROS Relate CRM Software component of Oracle Retail Applications (subcomponent: Internal Operatio
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation component of Oracle Retail Applicatio
Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of D
A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI.
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authen
An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD,
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipu
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure di
A vulnerability in the update mechanism of Subaru StarLink Harman head units 2017, 2018, and 2019 may give an attacker (
In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. This could lead to l
Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated
Vulnerability in the Oracle Communications Unified Inventory Management component of Oracle Communications Applications
A remote unauthenticated access vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modify
Philips ISCV application prior to version 2.3.0 has an insufficient session expiration vulnerability where an attacker c
A vulnerability in Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authentic
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain mode
An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorPara
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain
The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community
Vulnerability in the Oracle Communications Order and Service Management component of Oracle Communications Applications
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started