CVE Vulnerabilities in 2018

30 documented vulnerabilities published in 2018.

Other years: 2026 2025 2024 2023 2022 2021 2020

Top Affected Vendors in 2018

All CVEs from 2018

CVE-2018-11091
9.9 critical

An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. It is possible for an attacker to upload a script to issue operating system commands. This vulnerability occurs because an attacker is able to adjust the "HiddenFieldControlCustomWh

Mybiz Myprocurenet May 14, 2018
CVE-2018-9989
7.5 high

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.

Arm Mbed Tls Apr 10, 2018
CVE-2018-9988
7.5 high

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.

Arm Mbed Tls Apr 10, 2018
CVE-2017-12626
7.5 high

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).

Apache Poi Jan 29, 2018
CVE-2017-5754
5.6 medium

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

Intel Atom C Jan 4, 2018
CVE-2017-5753
5.6 medium

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

Intel Atom C Jan 4, 2018