Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2016-0738
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows …
Swift
after 2.3.0
HIGH 7.5
CVE-2016-0737
OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service …
Swift
after 2.3.0
MEDIUM 5.9
CVE-2015-8749
The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the conne…
Nova
12.0.1 / 2015.1.3+
MEDIUM 6.8
CVE-2015-5306
OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask c…
Ironic Inspector
Mitigation only
MEDIUM 5.0
CVE-2015-7713
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote…
Nova
2014.2.4 / 2015.1.2+
MEDIUM 6.8
CVE-2015-5286
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage q…
Image Registry And Delivery Service \(glance\)
after 2014.2.3
MEDIUM 5.5
CVE-2015-5251
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of …
Image Registry And Delivery Service \(glance\)
after 2014.2.3
MEDIUM 5.0
CVE-2015-5223
OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that refer…
Swift
after 2.3.0
MEDIUM 6.8
CVE-2015-3280
OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allo…
Nova
2014.2.4 / 2015.1.2+
MEDIUM 6.8
CVE-2015-3241
OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allow…
Nova
after 2015.1.1
MEDIUM 5.1
CVE-2015-0259
OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which …
Nova
2014.1.4 / 2014.2.3+
MEDIUM 6.5
CVE-2015-1195
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users t…
Image Registry And Delivery Service \(glance\)
2014.1.4 / 2014.2.2+
MEDIUM 6.5
CVE-2014-0204
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allow…
Keystone
2014.1.1+
MEDIUM 6.5
CVE-2014-3520
OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to …
Keystone
2013.2.4 / 2014.1.2+
MEDIUM 6.5
CVE-2014-8750
Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to acce…
Nova
2014.1.4+
HIGH 7.6
CVE-2014-3632
The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stac…
Neutron
after 2014.1.2
MEDIUM 6.0
CVE-2014-3476
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allo…
Keystone
2013.2.4 / 2014.1.2+
MEDIUM 5.5
CVE-2013-4471
The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, w…
Horizon
2013.2+
MEDIUM 6.0
CVE-2014-0162
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote …
Icehouse
Mitigation only
HIGH 7.8
CVE-2014-2828
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of serv…
Keystone
Mitigation only
MEDIUM 6.0
CVE-2014-0167
The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce R…
Compute
Patch available
MEDIUM 6.0
CVE-2014-0105
The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve use…
Python Keystoneclient
after 0.4.2
MEDIUM 5.0
CVE-2014-2237
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when i…
Keystone
Mitigation only
MEDIUM 5.8
CVE-2013-6396
The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allow…
Swift
Mitigation only
HIGH 7.1
CVE-2013-7130
The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, w…
Compute
Patch available
MEDIUM 5.5
CVE-2013-2104
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authen…
Python Keystoneclient
after 0.2.3
MEDIUM 5.0
CVE-2013-6419
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a reques…
Havana
Patch available
MEDIUM 6.4
CVE-2013-4497
The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an…
Havana
Mitigation only
MEDIUM 5.0
CVE-2013-4294
The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the …
Keystone
Patch available
MEDIUM 6.0
CVE-2013-2256
OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows r…
Nova
2013.1.3+