16,510 vulnerabilities published in 2018
In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of bounds write due
In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of bounds write due
In Android before the 2018-06-05 security patch level, NVIDIA Tegra X1 TZ contains a possible out of bounds write due to
An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauth
A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allo
The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). I
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize devic
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Ser
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Accessibili
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Bluetooth" compo
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "ATS" compon
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "IOHIDFamily
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "IOGraphics"
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Hypervisor"
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC<FileIO>::process function in tra
md_build_attribute in md4c.c in md4c 0.2.6 allows remote attackers to cause a denial of service (Segmentation fault and
In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Window
This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Mainten
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer w
The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. T
An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation th
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing an
The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attac
WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an
In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be trigg
Buffer might get used after it gets freed due to unlocking the mutex before freeing the buffer in all Android releases f
The value of fix_param->num_chans is received from firmware and if it is too large, an integer overflow can occur in wma
In the camera driver, an out-of-bounds access can occur due to an error in copying region params from user space in all
In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if the value of va
In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux K
While processing a DSP buffer in an audio driver's event handler, an index of a buffer is not checked before accessing t
improper validation of array index in WiFi driver function sapInterferenceRssiCount() leads to array out-of-bounds acces
In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux K
Buffer overflow can occur due to improper input validation in multiple WMA event handler functions in all Android releas
An arbitrary address write can occur if a compromised WLAN firmware sends incorrect data to WLAN driver in all Android r
In the function wma_pdev_div_info_evt_handler() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, Q
In the video driver function set_output_buffers(), binfo can be accessed after being freed in a failure scenario in all
Early or late retirement of rotation requests can result in a Use After Free condition in all Android releases from CAF
In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result
Buffer over flow can occur while processing a HTT_T2H_MSG_TYPE_TX_COMPL_IND message with an out-of-range num_msdus value
There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java binary file.
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started