Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2016-0738 OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows … Swift after 2.3.0 Fix from $1,9502016-01-29 HIGH 7.5 CVE-2016-0737 OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service … Swift after 2.3.0 Fix from $1,9502016-01-29 MEDIUM 5.9 CVE-2015-8749 The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the conne… Nova 12.0.1 / 2015.1.3+ Fix from $1,6002016-01-15 MEDIUM 6.8 CVE-2015-5306 OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask c… Ironic Inspector Mitigation only Fix from $1,6002015-11-25 MEDIUM 5.0 CVE-2015-7713 OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote… Nova 2014.2.4 / 2015.1.2+ Fix from $1,6002015-10-29 MEDIUM 6.8 CVE-2015-5286 OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage q… Image Registry And Delivery Service \(glance\) after 2014.2.3 Fix from $1,6002015-10-26 MEDIUM 5.5 CVE-2015-5251 OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of … Image Registry And Delivery Service \(glance\) after 2014.2.3 Fix from $1,6002015-10-26 MEDIUM 5.0 CVE-2015-5223 OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that refer… Swift after 2.3.0 Fix from $1,6002015-10-26 MEDIUM 6.8 CVE-2015-3280 OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allo… Nova 2014.2.4 / 2015.1.2+ Fix from $1,6002015-10-26 MEDIUM 6.8 CVE-2015-3241 OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allow… Nova after 2015.1.1 Fix from $1,6002015-09-08 MEDIUM 5.1 CVE-2015-0259 OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which … Nova 2014.1.4 / 2014.2.3+ Fix from $1,6002015-04-01 MEDIUM 6.5 CVE-2015-1195 The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users t… Image Registry And Delivery Service \(glance\) 2014.1.4 / 2014.2.2+ Fix from $1,6002015-01-21 MEDIUM 6.5 CVE-2014-0204 OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allow… Keystone 2014.1.1+ Fix from $1,6002014-11-03 MEDIUM 6.5 CVE-2014-3520 OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to … Keystone 2013.2.4 / 2014.1.2+ Fix from $1,6002014-10-26 MEDIUM 6.5 CVE-2014-8750 Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to acce… Nova 2014.1.4+ Fix from $1,6002014-10-15 HIGH 7.6 CVE-2014-3632 The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stac… Neutron after 2014.1.2 Fix from $1,9502014-10-07 MEDIUM 6.0 CVE-2014-3476 OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allo… Keystone 2013.2.4 / 2014.1.2+ Fix from $1,6002014-06-17 MEDIUM 5.5 CVE-2013-4471 The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, w… Horizon 2013.2+ Fix from $1,6002014-05-14 MEDIUM 6.0 CVE-2014-0162 The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote … Icehouse Mitigation only Fix from $1,6002014-04-27 HIGH 7.8 CVE-2014-2828 The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of serv… Keystone Mitigation only Fix from $1,9502014-04-15 MEDIUM 6.0 CVE-2014-0167 The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce R… Compute Patch available Fix from $1,6002014-04-15 MEDIUM 6.0 CVE-2014-0105 The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve use… Python Keystoneclient after 0.4.2 Fix from $1,6002014-04-15 MEDIUM 5.0 CVE-2014-2237 The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when i… Keystone Mitigation only Fix from $1,6002014-04-01 MEDIUM 5.8 CVE-2013-6396 The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allow… Swift Mitigation only Fix from $1,6002014-02-18 HIGH 7.1 CVE-2013-7130 The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, w… Compute Patch available Fix from $1,9502014-02-06 MEDIUM 5.5 CVE-2013-2104 python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authen… Python Keystoneclient after 0.2.3 Fix from $1,6002014-01-21 MEDIUM 5.0 CVE-2013-6419 Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a reques… Havana Patch available Fix from $1,6002014-01-07 MEDIUM 6.4 CVE-2013-4497 The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an… Havana Mitigation only Fix from $1,6002013-11-05 MEDIUM 5.0 CVE-2013-4294 The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the … Keystone Patch available Fix from $1,6002013-09-23 MEDIUM 6.0 CVE-2013-2256 OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows r… Nova 2013.1.3+ Fix from $1,6002013-09-16