16,510 vulnerabilities published in 2018
An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attacker
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter cou
In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.
Kaizen Asset Manager (Enterprise Edition) and Training Manager (Enterprise Edition) allow a remote attacker to achieve a
An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even th
The Pulse Secure Desktop (macOS) has a Privilege Escalation Vulnerability.
Untrusted search path vulnerability in Multiple Yayoi 17 Series products (Yayoi Kaikei 17 Series Ver.23.1.1 and earlier,
Untrusted search path vulnerability in Multiple Yayoi 17 Series products (Yayoi Kaikei 17 Series Ver.23.1.1 and earlier,
Untrusted search path vulnerability in installer of ChatWork Desktop App for Windows 2.3.0 and earlier allows an attacke
Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart
An exploitable code execution vulnerability exists in the connect functionality of ProtonVPN VPN client 1.5.1. A special
An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in parse_relations in os/stora
An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in next_string in os/storage/a
SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
A heap-based buffer overflow in PotPlayerMini.exe in PotPlayer 1.7.8556 allows remote attackers to execute arbitrary cod
An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running o
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform befor
A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists i
In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only mem
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vul
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vul
An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable com
Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated
Directory permissions in the Intel OpenVINO Toolkit for Windows before version 2018.1.265 may allow an authenticated use
Privilege escalation in file permissions in Intel Computing Improvement Program before version 2.2.0.03942 may allow an
Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user
Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges.
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an
A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted PDF file, aka "Word P
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka "Windows S
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Window
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje
An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanit
An issue was discovered in mgetty before 1.2.1. In contrib/scrts.c, a stack-based buffer overflow can be triggered via a
An issue was discovered in mgetty before 1.2.1. In contrib/next-login/login.c, the command-line parameter username is pa
An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized
An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized
A maliciously crafted project file may cause a buffer overflow, which may allow the attacker to execute arbitrary code t
An issue has been found in doc2txt through 2014-03-19. It is a heap-based buffer overflow in the function Storage::init
Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials.
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while loadin
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while proces
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started