16,510 vulnerabilities published in 2018
When a malformed command is sent to the device programmer, an out-of-bounds access can occur in Snapdragon Automobile, S
While loading a service image, an untrusted pointer dereference can occur in Snapdragon Mobile in versions SD 835, SDA66
In the device programmer target-side code for firehose, a string may not be properly NULL terminated can lead to a incor
Potential buffer overflow in Video due to lack of input validation in input and output values in Snapdragon Automobile,
Possible buffer overflow in OEM crypto function due to improper input validation in Snapdragon Automobile, Snapdragon Mo
Possible buffer overflow in DRM Trusted application due to lack of check function return values in Snapdragon Automobile
The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversa
Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection S
Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case
There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a
A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-
An exploitable arbitrary write vulnerability exists in the open document format parser of the Atlantis Word Processor, v
An exploitable out-of-bounds write vulnerability exists in the PNG implementation of Atlantis Word Processor, version 3.
An exploitable uninitialized pointer vulnerability exists in the rich text format parser of Atlantis Word Processor, ver
In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malici
A Vulnerability in the configdownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8
A vulnerability in the configuration of a local database installed as part of the Cisco Energy Management Suite (CEMS) c
In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when
Two stack-based buffer overflow vulnerabilities have been discovered in CX-One Versions 4.42 and prior (CX-Programmer Ve
Local attackers can trigger a stack-based buffer overflow on vulnerable installations of Antiy-AVL ATool security manage
In V4L2SliceVideoDecodeAccelerator::Dequeue of v4l2_slice_video_decode_accelerator.cc, there is a possible out of bounds
In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to
In lppTransposer of lpp_tran.cpp there is a possible out of bounds write due to missing bounds check. This could lead to
In CAacDecoder_Init of aacdecoder.cpp, there is a possible out of bounds write due to a missing bounds check. This could
In CAacDecoder_Init of aacdecoder.cpp, there is a possible out-of-bound write due to a missing bounds check. This could
In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure default value. This could
In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninitialized data. This c
In rw_t2t_handle_tlv_detect of rw_t2t_ndef.cc, there is a possible out-of-bounds write due to a missing bounds check. Th
In persist_set_key and other functions of cryptfs.cpp, there is a possible out-of-bounds write due to an uncaught error.
In HID_DevAddRecord of hidd_api.cc, there is a possible out-of-bounds write due to a missing bounds check. This could le
On Pixel devices there is a bug causing verified boot to show the same certificate fingerprint despite using different s
In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escala
Authentication Abuse vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows loca
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Userspace can
In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. T
In impd_parse_drc_ext_v1 of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds chec
In impd_parse_filt_block of impd_drc_dynamic_payload.c there is a possible out of bounds write due to missing bounds che
In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missi
In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bo
In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to mi
In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS pri
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS pri
An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in m
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonat
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started