16,510 vulnerabilities published in 2018
In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote t
In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. This could lead to remo
A other vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID:
In Exiv2 0.26, there is a reachable assertion in the readHeader function in bigtiffimage.cpp, which will lead to a remot
In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::IptcData::printStructure function in iptc.cpp, relat
In Exiv2 0.26, there is an integer overflow leading to a heap-based buffer over-read in the Exiv2::getULong function in
A stack-based buffer over-read in the ComputeResizeImage function in the MagickCore/accelerate.c file of ImageMagick 7.0
An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within
A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vul
A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could en
In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space
In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved
In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evalu
A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to st
Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessi
Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing t
Under certain conditions a malicious user provoking an out of bounds buffer overflow can prevent legitimate users from a
A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to ob
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (
Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (
Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 201
Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL
A remote information disclosure in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all vers
A Remote click jacking vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.
A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v
A remote arbitrary file download and disclosure of information vulnerability in HPE Intelligent Management Center (iMC)
A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 wa
A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 wa
A remote clickjacking vulnerability in HPE Matrix Operating Environment version v7.6 was found.
A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found.
A remote information disclosure vulnerability in HPE Matrix Operating Environment version v7.6 was found.
A remote denial of service vulnerability in HPE Version Control Repository Manager (VCRM) in all versions prior to 7.6 w
A Local Arbitrary File Download vulnerability in HPE Intelligent Management Center (IMC) version PLAT 7.2 E0403P06 was f
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter
The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Ooz
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not
The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof
DBManager in Symantec Altiris Deployment Solution 6.9.x before DS 6.9 SP4 allows remote attackers to cause a denial of s
An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master proce
Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base
The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sen
The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asteris
IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user
The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image d
Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 t
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started