CVE-2018-1002105
- EPSS 90.7%
- Veröffentlicht 05.12.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:38
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server...
CVE-2018-19475
- EPSS 63.59%
- Veröffentlicht 23.11.2018 05:29:03
- Zuletzt bearbeitet 21.11.2024 03:57:59
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
CVE-2018-19476
- EPSS 0.82%
- Veröffentlicht 23.11.2018 05:29:03
- Zuletzt bearbeitet 21.11.2024 03:57:59
psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.
CVE-2018-19477
- EPSS 0.82%
- Veröffentlicht 23.11.2018 05:29:03
- Zuletzt bearbeitet 21.11.2024 03:57:59
psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.
CVE-2018-18559
- EPSS 0.84%
- Veröffentlicht 22.10.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:09
In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET socket. This issue exists because of the 15fe076edea787807a7cdc168df832544b58eba6 incomplete fix for a ra...
CVE-2018-14645
- EPSS 0.23%
- Veröffentlicht 21.09.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:29
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
CVE-2018-3830
- EPSS 0.71%
- Veröffentlicht 19.09.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:07
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
CVE-2018-10937
- EPSS 0.33%
- Veröffentlicht 11.09.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:20
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.
CVE-2018-14632
- EPSS 0.51%
- Veröffentlicht 06.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:28
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service whi...
CVE-2018-16540
- EPSS 0.28%
- Veröffentlicht 05.09.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:56
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.