CVE-2018-1000865
- EPSS 0.64%
- Published 10.12.2018 14:29:01
- Last modified 21.11.2024 03:40:31
A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java that allows attackers with Job/Configure permission to execute arbitrary code on the J...
CVE-2018-1000866
- EPSS 0.64%
- Published 10.12.2018 14:29:01
- Last modified 21.11.2024 03:40:31
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java tha...
CVE-2018-18311
- EPSS 13.02%
- Published 07.12.2018 21:29:00
- Last modified 21.11.2024 03:55:40
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CVE-2018-1002105
- EPSS 90.7%
- Published 05.12.2018 21:29:00
- Last modified 21.11.2024 03:40:38
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server...
CVE-2018-19475
- EPSS 66.26%
- Published 23.11.2018 05:29:03
- Last modified 21.11.2024 03:57:59
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
CVE-2018-19476
- EPSS 0.72%
- Published 23.11.2018 05:29:03
- Last modified 21.11.2024 03:57:59
psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.
CVE-2018-19477
- EPSS 0.72%
- Published 23.11.2018 05:29:03
- Last modified 21.11.2024 03:57:59
psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.
CVE-2018-18559
- EPSS 1.14%
- Published 22.10.2018 16:29:00
- Last modified 21.11.2024 03:56:09
In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET socket. This issue exists because of the 15fe076edea787807a7cdc168df832544b58eba6 incomplete fix for a ra...
CVE-2018-14645
- EPSS 0.23%
- Published 21.09.2018 13:29:00
- Last modified 21.11.2024 03:49:29
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
CVE-2018-3830
- EPSS 0.71%
- Published 19.09.2018 19:29:01
- Last modified 21.11.2024 04:06:07
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.