Redhat Openstack vulnerabilities
208 known vulnerabilities affecting redhat/openstack.
Total CVEs
208
CISA KEV
0
Public exploits
9
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH63MEDIUM111LOW11
Vulnerabilities
Page 11 of 11
CVE-2017-3653P4LOWCVSS 3.1v122017-08-08
CVE-2017-3653 [LOW] CVE-2017-3653: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnera
nvd
CVE-2016-6888P4MEDIUMCVSS 4.4v6.0v7.0+4 more2016-12-10
CVE-2016-6888 [MEDIUM] CWE-190 CVE-2016-6888: Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator)
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.
nvd
CVE-2018-2767P4LOWCVSS 3.1v122018-07-18
CVE-2018-2767 [LOW] CVE-2018-2767: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encrypt
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of t
nvd
CVE-2020-1736P4LOWCVSS 3.3v132020-03-16
CVE-2020-1736 [LOW] CWE-732 CVE-2020-1736: A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This could lead to the disclosure of sensiti
nvd
CVE-2022-4134P4LOWCVSS 2.8v13v16.1+3 more2023-03-06
CVE-2022-4134 [LOW] CWE-829 CVE-2022-4134: A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tam
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
nvd
CVE-2014-7230P4LOWCVSS 2.1v5.02014-10-08
CVE-2014-7230 [LOW] CWE-200 CVE-2014-7230: The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
nvd
CVE-2014-7231P4LOWCVSS 2.1v5.02014-10-08
CVE-2014-7231 [LOW] CWE-200 CVE-2014-7231: The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove b
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
nvd
CVE-2014-3615P4LOWCVSS 2.1v5.02014-11-01
CVE-2014-3615 [LOW] CWE-200 CVE-2014-3615: The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a hi
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
nvd
← Previous11 / 11