16,510 vulnerabilities published in 2018
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Bluetooth"
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Firmware" c
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "AMD" compon
md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block.
An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attacke
A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affe
When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be ap
The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the upda
The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a specia
The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating sys
A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If
The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users.
The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using
The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the loc
In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_ch
In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux K
There is a heap out of bounds read in radare2 2.6.0 in _6502_op() in libr/anal/p/anal_6502.c via a crafted iNES ROM bina
An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party co
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Servi
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulne
The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of s
User process can perform the kernel DOS in ashmem when doing cache maintenance operation in all Android releases(Android
In the MDSS driver in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux ke
Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable t
The libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remo
The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote at
The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-2
The libfsntfs_mft_entry_read_header function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote atta
The libfsntfs_security_descriptor_values_free function in libfsntfs_security_descriptor_values.c in libfsntfs through 20
The libfsntfs_mft_entry_read_attributes function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote
The liblnk_data_string_get_utf8_string_size function in liblnk_data_string.c in liblnk through 2018-04-19 allows remote
The liblnk_location_information_read_data function in liblnk_location_information.c in liblnk through 2018-04-19 allows
The liblnk_data_block_read function in liblnk_data_block.c in liblnk through 2018-04-19 allows remote attackers to cause
A vulnerability in the session identification management functionality of the web-based management interface for Cisco M
A vulnerability in vpnva-6.sys for 32-bit Windows and vpnva64-6.sys for 64-bit Windows of Cisco AnyConnect Secure Mobili
An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the
An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion
U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result
miniSphere version 5.2.9 and earlier contains a Integer Overflow vulnerability in layer_resize() function in map_engine.
In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur d
ntfs_read_locked_inode in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a use-aft
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started