← Back

Openstack

openstack

Vendor: Redhat • 210 CVEs

CVEs (210)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
QemuRedhat
3Debian Linux
OpenstackQemu
May 13, 2026
May 23, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture.
2Openstack
Redhat
2Manila
Openstack
May 13, 2026
Apr 21, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" for...Show more
Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form.Show less
3Nagios
RedhatSnoopy
3Nagios
OpenstackSnoopy
May 13, 2026
Mar 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
3Debian
RedhatSnoopy
3Debian Linux
OpenstackSnoopy
May 13, 2026
Mar 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Snoopy allows remote attackers to execute arbitrary commands.
3Nagios
RedhatSnoopy
3Nagios
OpenstackSnoopy
May 13, 2026
Mar 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
3Debian
QemuRedhat
4Debian Linux
OpenstackQemu+1 more
May 13, 2026
Mar 27, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control tra...Show more
The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence.Show less
7Debian
FedoraprojectJqueryui+4 more
13Application Express
Business IntelligenceDebian Linux+10 more
May 13, 2026
Mar 15, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
3Debian
QemuRedhat
4Debian Linux
OpenstackQemu+1 more
May 6, 2026
Dec 23, 2016
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user ins...Show more
Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw to crash the Qemu process instance on the host, resulting in DoS.Show less
3Debian
QemuRedhat
4Debian Linux
OpenstackQemu+1 more
May 6, 2026
Dec 23, 2016
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to l...Show more
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.Show less
3Debian
QemuRedhat
4Debian Linux
OpenstackQemu+1 more
May 6, 2026
Dec 23, 2016
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could us...Show more
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.Show less
3Opensuse
QemuRedhat
4Leap
OpenstackQemu+1 more
May 6, 2026
Dec 10, 2016
N/A· v4
6.0 MEDIUM· v3
1.9 LOW· v2
Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEM...Show more
Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly unplugging a USB device.Show less
3Opensuse
QemuRedhat
4Leap
OpenstackQemu+1 more
May 6, 2026
Dec 10, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descr...Show more
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.Show less
3Debian
QemuRedhat
4Debian Linux
OpenstackQemu+1 more
May 6, 2026
Dec 10, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation co...Show more
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.Show less
4Debian
OpensuseQemu+1 more
5Debian Linux
LeapOpenstack+2 more
May 6, 2026
Nov 4, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit th...Show more
The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.Show less
4Debian
OpensuseQemu+1 more
5Debian Linux
LeapOpenstack+2 more
May 6, 2026
Nov 4, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for...Show more
The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position.Show less
4Debian
OpensuseQemu+1 more
5Debian Linux
LeapOpenstack+2 more
May 6, 2026
Nov 4, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving...Show more
The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider greater than baud base.Show less
4Debian
OpensuseQemu+1 more
5Debian Linux
LeapOpenstack+2 more
May 6, 2026
Nov 4, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the n...Show more
The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process.Show less
5Debian
MariadbOracle+2 more
12Debian Linux
Enterprise LinuxEnterprise Linux Desktop+9 more
May 6, 2026
Sep 20, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5...Show more
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.Show less
5Canonical
DebianOracle+2 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+10 more
May 6, 2026
Aug 2, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion...Show more
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.Show less
2Canonical
Redhat
2Openstack
Openstack Ironic
May 6, 2026
Jul 12, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address o...Show more
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.Show less