CVE-2019-0211
- EPSS 89.55%
- Veröffentlicht 08.04.2019 22:29:00
- Zuletzt bearbeitet 27.10.2025 17:37:51
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with...
CVE-2019-3876
- EPSS 0.14%
- Veröffentlicht 01.04.2019 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:46
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via Jav...
CVE-2019-1002100
- EPSS 4.87%
- Veröffentlicht 01.04.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:17:42
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Ty...
CVE-2019-1002101
- EPSS 49.27%
- Veröffentlicht 01.04.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:17:42
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar b...
CVE-2019-1003040
- EPSS 2.06%
- Veröffentlicht 28.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:17:47
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.
CVE-2019-1003041
- EPSS 2.06%
- Veröffentlicht 28.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:17:47
A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.
CVE-2019-3826
- EPSS 1.46%
- Veröffentlicht 26.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:37
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persis...
- EPSS 94.43%
- Veröffentlicht 25.03.2019 19:29:02
- Zuletzt bearbeitet 07.11.2025 19:36:46
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly le...
CVE-2019-7221
- EPSS 0.05%
- Veröffentlicht 21.03.2019 16:01:10
- Zuletzt bearbeitet 21.11.2024 04:47:46
The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.
CVE-2018-20615
- EPSS 0.17%
- Veröffentlicht 21.03.2019 16:00:36
- Zuletzt bearbeitet 21.11.2024 04:01:51
An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are s...