CVEs (210)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one...Show more |
2Openstack Redhat3Openstack Openstack For Ibm PowerTripleo AnsibleJun 17, 2026 Mar 23, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the rele...Show more |
2Openstack Redhat3Openstack Openstack For Ibm PowerTripleo AnsibleJun 17, 2026 Mar 23, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the rele...Show more |
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images. |
2Openstack Redhat4Barbican OpenstackOpenstack For Ibm Power+1 moreJun 17, 2026 Jan 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API. |
A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead...Show more |
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the...Show more |
2Openstack Redhat2Openstack Tripleo Heat TemplatesJun 17, 2026 Mar 23, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is vi...Show more |
3Fedoraproject LinuxRedhat263scale Api Management Codeready Linux BuilderEnterprise Linux+23 moreJun 17, 2026 Mar 4, 2022 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due...Show more |
1Redhat 9Ansible Automation Platform Early Access Ansible EngineEnterprise Linux+6 moreJun 17, 2026 Mar 3, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulner...Show more |
3Debian QemuRedhat10Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+7 moreJun 17, 2026 Feb 18, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest cou...Show more |
5Canonical DebianFedoraproject+2 more25Codeready Linux Builder Debian LinuxEnterprise Linux+22 moreJun 17, 2026 Feb 18, 2022 N/A· v4 8.1 HIGH· v3 8.5 HIGH· v2 A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation. |
5Canonical DebianFedoraproject+2 more24Codeready Linux Builder Debian LinuxEnterprise Linux+21 moreNov 21, 2024 Feb 18, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required. |
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data conf...Show more |
5Fedoraproject Lldpd ProjectOpenvswitch+2 more17Enterprise Linux FedoraLldpd+14 moreJun 17, 2026 Mar 18, 2021 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest...Show more |
5Canonical DebianOpensuse+2 more10Debian Linux Enterprise LinuxEnterprise Linux Aus+7 moreJun 17, 2026 Oct 7, 2020 N/A· v4 6.6 MEDIUM· v3 6.5 MEDIUM· v2 Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws....Show more |
6Canonical DebianFedoraproject+3 more7Debian Linux Enterprise LinuxFedora+4 moreJun 17, 2026 Aug 31, 2020 N/A· v4 5.0 MEDIUM· v3 4.4 MEDIUM· v2 An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[409...Show more |
7Apache CanonicalDebian+4 more25Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+22 moreJun 17, 2026 Aug 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Confi...Show more |
5Canonical DebianLibslirp Project+2 more6Debian Linux Enterprise LinuxLeap+3 moreJun 17, 2026 Jul 9, 2020 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping...Show more |
3Hibernate QuarkusRedhat10Build Of Quarkus Decision ManagerFuse+7 moreJun 17, 2026 Jul 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or G...Show more |