16,510 vulnerabilities published in 2018
In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial
In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result
The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha
An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a
The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of s
The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of servi
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitiv
NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Grap
Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file vi
Espruino before 1.98 allows attackers to cause a denial of service (application crash) with a user crafted input file vi
Espruino before 1.98 allows attackers to cause a denial of service (application crash) with a user crafted input file vi
Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file vi
Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file vi
Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file vi
The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management App
The Linux Kernel versions 4.14, 4.15, and 4.16 has a null pointer dereference which can result in an out of memory (OOM)
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write
Buffer over -read can occur while processing a FILS authentication frame in all Android releases from CAF (Android for M
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Intel Graph
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Graphics Dr
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Bluetooth"
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Firmware" c
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "AMD" compon
md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block.
An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attacke
A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affe
When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be ap
The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the upda
The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a specia
The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating sys
A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If
The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users.
The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using
The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the loc
In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_ch
In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux K
There is a heap out of bounds read in radare2 2.6.0 in _6502_op() in libr/anal/p/anal_6502.c via a crafted iNES ROM bina
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started