cbcvebase.

Redhat Openstack vulnerabilities

208 known vulnerabilities affecting redhat/openstack.

Total CVEs
208
CISA KEV
0
Public exploits
9
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH63MEDIUM111LOW11

Vulnerabilities

Page 1 of 11
CVE-2016-6662P1CRITICALCVSS 9.8ExploitedPoCv5.0v6.0+3 more2016-09-20
CVE-2016-6662 [CRITICAL] CWE-264 CVE-2016-6662: Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting genera
nvd
CVE-2018-3639P1MEDIUMCVSS 5.5ExploitedPoCRansomwarev7.0v8+4 more2018-05-22
CVE-2018-3639 [MEDIUM] CWE-203 CVE-2018-3639: Systems with microprocessors utilizing speculative execution and speculative execution of memory rea Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
nvd
CVE-2020-10684P1HIGHCVSS 7.1Exploitedv10v132020-03-24
CVE-2020-10684 [HIGH] CWE-94 CVE-2020-10684: A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2 A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansibl
nvd
CVE-2018-1000115P2HIGHCVSS 7.5PoCv8v9+3 more2018-03-05
CVE-2018-1000115 [HIGH] CWE-400 CVE-2018-1000115: Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplific Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via netwo
nvd
CVE-2018-11218P2CRITICALCVSS 9.8PoCv10v132018-06-17
CVE-2018-11218 [CRITICAL] CWE-787 CVE-2018-11218: Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12 Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.
nvd
CVE-2017-7481P3CRITICALCVSS 9.8Exploitedv10v112018-07-19
CVE-2017-7481 [CRITICAL] CWE-20 CVE-2017-7481: Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now marked as 'unsafe' and is not eval
nvd
CVE-2016-9587P2HIGHCVSS 8.1PoCv112018-04-24
CVE-2016-9587 [HIGH] CWE-20 CVE-2016-9587: Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's hand Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible ser
nvd
CVE-2020-9490P2HIGHCVSS 7.5v16.12020-08-07
CVE-2020-9490 [HIGH] CWE-444 CVE-2020-9490: Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' heade Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
nvd
CVE-2013-2121P3MEDIUMCVSS 6.0PoCv3.02013-07-31
CVE-2013-2121 [MEDIUM] CWE-94 CVE-2013-2121: Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2. Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.
nvd
CVE-2015-3456P3HIGHCVSS 7.7PoCv4.0v5.0+2 more2015-05-13
CVE-2015-3456 [HIGH] CWE-119 CVE-2015-3456: The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local gue The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
nvd
CVE-2019-9515P3HIGHCVSS 7.5v142019-08-13
CVE-2019-9515 [HIGH] CWE-400 CVE-2019-9515: Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of s Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently th
nvd
CVE-2019-9514P3HIGHCVSS 7.5v142019-08-13
CVE-2019-9514 [HIGH] CWE-400 CVE-2019-9514: Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of serv Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both
nvd
CVE-2013-2113P3MEDIUMCVSS 6.0PoCv3.02013-07-31
CVE-2013-2113 [MEDIUM] CWE-264 CVE-2013-2113: The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote a The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.
nvd
CVE-2014-5008P2CRITICALCVSS 9.8v5.0v6.02017-03-31
CVE-2014-5008 [CRITICAL] CWE-77 CVE-2014-5008: Snoopy allows remote attackers to execute arbitrary commands. Snoopy allows remote attackers to execute arbitrary commands.
nvd
CVE-2015-1842P2CRITICALCVSS 10.0≤ 6.02015-04-10
CVE-2015-1842 [CRITICAL] CWE-255 CVE-2015-1842: The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a defau The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.
nvd
CVE-2017-2637P2CRITICALCVSS 10.0v7.0v8+2 more2018-07-26
CVE-2017-2637 [CRITICAL] CWE-306 CVE-2017-2637: A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable li A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no-authentication or encryption. Anyone able to make a TCP connection to any compute host IP address, including 127.0.0.1, other loop
nvd
CVE-2017-2620P2CRITICALCVSS 9.9v5.0v6.0+4 more2018-07-27
CVE-2017-2620 [CRITICAL] CWE-787 CVE-2017-2620: Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of th
nvd
CVE-2017-10906P2CRITICALCVSS 9.8v132017-12-08
CVE-2017-10906 [CRITICAL] CVE-2017-10906: Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an att Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.
nvd
CVE-2016-9603P3CRITICALCVSS 9.9v5.0v6.0+4 more2018-07-27
CVE-2016-9603 [CRITICAL] CWE-122 CVE-2016-9603: A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver s A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute a
nvd
CVE-2019-10192P3HIGHCVSS 7.2v9v10+2 more2019-07-11
CVE-2019-10192 [HIGH] CWE-122 CVE-2019-10192: A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL encoding to write up to 3 bytes beyond the end of a heap-allocated buffer.
nvd
1 / 11Next →
Redhat Openstack vulnerabilities | cvebase