16,510 vulnerabilities published in 2018
A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi
A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.c
The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes
Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.ph
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE
tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.
A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to
The Enterprise Console in Cisco AppDynamics App iQ Platform before 4.4.3.10598 (HF4) allows SQL injection, aka the Secur
tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instan
The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external
The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class inst
The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows extern
The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server.
A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect
Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume t
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corrup
An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issu
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed
Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presu
Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we pre
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerabili
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption.
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will b
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corr
Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T
Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45
A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potenti
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thun
The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing J
Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a con
Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorre
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the m
The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we pre
Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume t
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potenti
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resu
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroye
When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root obje
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and
Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how
A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and
An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability di
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs
Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence o
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started