CVEs (210)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API...Show more |
2Openstack Redhat2Image Registry And Delivery Service (glance) OpenstackMay 6, 2026 Jan 23, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state. |
2Openstack Redhat2Image Registry And Delivery Service (glance) OpenstackMay 6, 2026 Jan 7, 2015 N/A· v4 N/A· v3 5.5 MEDIUM· v2 The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image locati...Show more |
3Fedoraproject OpenstackRedhat3Fedora NeutronOpenstackMay 6, 2026 Nov 24, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration. |
5Canonical DebianOpensuse+2 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Nov 1, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution. |
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state. |
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request. |
2Openstack Redhat4Cinder NovaOpenstack+1 moreMay 6, 2026 Oct 8, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local use...Show more |
3Canonical OpenstackRedhat5Cinder NovaOpenstack+2 moreMay 6, 2026 Oct 8, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by...Show more |
3Canonical OpenstackRedhat3Keystone OpenstackUbuntu LinuxMay 6, 2026 Oct 2, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated...Show more |
3Canonical OpenstackRedhat6Neutron OpenstackOslo+3 moreMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authe...Show more |
OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, sets gpgcheck to 0 for certain templates, which disables GPG signature checking on downloaded packages and allows man...Show more |
OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, sets sslverify to false for certain Yum repositories, which disables SSL protection and allows man-in-the-middle atta...Show more |
OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, uses an HTTP connection to download (1) packages and (2) signing keys from Yum repositories, which allows man-in-the-...Show more |
The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenStack Platform 4.0, disables authentication for Qpid, which allows remote...Show more |
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections. |
5Canonical DebianOpensuse+2 more6Debian Linux LeapLibyaml+3 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code vi...Show more |
The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffin...Show more |
3Canonical OpenstackRedhat3Keystone OpenstackUbuntu LinuxApr 29, 2026 Dec 14, 2013 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by ge...Show more |
rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a symlink attack on /tmp/magpie_cache. |