16,510 vulnerabilities published in 2018
Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and
Microsoft ChakraCore allows an attacker to bypass Control Flow Guard (CFG) in conjunction with another vulnerability to
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions with
It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users'
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The att
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The at
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack
Directory traversal in the HTTP server on Yawcam 0.2.6 through 0.6.0 devices allows attackers to read arbitrary files th
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while fl
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while pe
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while up
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, userspac
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, if users
Directory traversal vulnerability in the web application in Symmetricom s350i 2.70.15 allows remote attackers to read ar
In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash. This was addr
An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. We
Cheetah Mobile CM Browser 5.22.06.0012, when installed on unspecified "older" Android platforms, allows Same Origin Poli
Cheetah Mobile Armorfly Browser & Downloader 1.1.05.0010, when installed on unspecified "older" Android platforms, allow
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication,
node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information
Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers
An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmen
An information disclosure vulnerability in the Android framework (clipboardservice). Product: Android. Versions: 5.1.1,
In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which
A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters. Product: Android. V
A vulnerability in the Android media framework (libavc) related to handling dec_hdl memory allocation failures. Product:
A vulnerability in the Android media framework (libhevc) related to handling ps_codec_obj memory allocation failures. Pr
In the ihevcd_decode function of ihevcd_decode.c, there is an infinite loop due to an incomplete frame error. This could
In the ihevcd_parse_slice_header function of ihevcd_parse_slice_header.c a slice address of zero after the first slice c
In ihevcd_decode.c there is a possible infinite loop due to bytes for an sps of unsupported resolution resulting in the
A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1
In the ihevcd_parse_sps function of ihevcd_parse_headers.c, several parameter values could be negative which could lead
In several places in ihevcd_decode.c, a dead loop could occur due to incomplete frames which could lead to memory leaks.
In the ihevcd_parse_slice.c function, slave threads are not joined if there is an error. This could lead to a remote den
A vulnerability in the Android media framework (ex) related to composition of frames lacking a color map. Product: Andro
In Bitmap.ccp if Bitmap.nativeCreate fails an out of memory exception is not thrown leading to a java.io.IOException lat
An information disclosure vulnerability in the Android media framework (av) related to id3 unsynchronization. Product: A
An information disclosure vulnerability in the Android media framework (mediadrm). Product: Android. Versions: 5.1.1, 6.
An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 5.1.1,
An information disclosure vulnerability in the Android media framework (aacdec). Product: Android. Versions: 5.1.1, 6.0,
An information disclosure vulnerability in the Android media framework (stagefright mpeg4writer). Product: Android. Vers
In bta_scan_results_cb_impl of btif_ble_scanner.cc, there is possible resource exhaustion if a large number of repeated
In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service o
A denial of service vulnerability in the Upstream kernel synaptics touchscreen controller. Product: Android. Versions: A
An information disclosure vulnerability in the Upstream kernel kernel. Product: Android. Versions: Android kernel. Andro
An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/d
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (router unreachable/unresponsive) via a flo
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of t
Scan for 2018 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started