cbcvebase.

Redhat Openstack vulnerabilities

208 known vulnerabilities affecting redhat/openstack.

Total CVEs
208
CISA KEV
0
Public exploits
9
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH63MEDIUM111LOW11

Vulnerabilities

Page 2 of 11
CVE-2015-3214P3MEDIUMCVSS 6.9PoCv5.0v6.02015-08-31
CVE-2015-3214 [MEDIUM] CWE-119 CVE-2015-3214: The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not dist The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
nvd
CVE-2019-10193P3HIGHCVSS 7.2v9v10+2 more2019-07-11
CVE-2019-10193 [HIGH] CWE-121 CVE-2019-10193: A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of up to 12 bytes past the end of a stack-allocated buffer.
nvd
CVE-2014-5009P3CRITICALCVSS 9.8v5.0v6.02017-03-31
CVE-2014-5009 [CRITICAL] CVE-2014-5009: Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due t Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
nvd
CVE-2008-7313P3CRITICALCVSS 9.8v5.0v6.02017-03-31
CVE-2008-7313 [CRITICAL] CVE-2008-7313: The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: t The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
nvd
CVE-2015-7512P3CRITICALCVSS 9.0v5.02016-01-08
CVE-2015-7512 [CRITICAL] CWE-120 CVE-2015-7512: Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larg Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.
nvd
CVE-2019-10141P3CRITICALCVSS 9.1v10v13+2 more2019-07-30
CVE-2019-10141 [CRITICAL] CWE-89 CVE-2019-10141: A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint).
nvd
CVE-2017-2615P3CRITICALCVSS 9.1v5.0v6.0+4 more2018-07-03
CVE-2017-2615 [CRITICAL] CWE-787 CVE-2017-2615: Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-o Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privi
nvd
CVE-2015-5165P3CRITICALCVSS 9.3v5.0v6.02015-08-12
CVE-2015-5165 [CRITICAL] CWE-908 CVE-2015-5165: The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
nvd
CVE-2015-3209P3HIGHCVSS 7.5v5.02015-06-15
CVE-2015-3209 [HIGH] CWE-787 CVE-2015-3209: Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitr Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
nvd
CVE-2018-10899P3HIGHCVSS 8.8v132019-08-01
CVE-2018-10899 [HIGH] CWE-20 CVE-2018-10899: A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.
nvd
CVE-2018-10915P3HIGHCVSS 7.5v12v132018-08-09
CVE-2018-10915 [HIGH] CWE-89 CVE-2018-10915: A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to prop A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher pri
nvd
CVE-2015-5741P3CRITICALCVSS 9.8v7.0v82020-02-08
CVE-2015-5741 [CRITICAL] CWE-444 CVE-2015-5741: The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields.
nvd
CVE-2013-4182P3HIGHCVSS 7.5v3.02013-09-16
CVE-2013-4182 [HIGH] CWE-264 CVE-2013-4182: app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
nvd
CVE-2014-3691P3HIGHCVSS 7.5v4.0v5.02015-03-09
CVE-2014-3691 [HIGH] CWE-310 CVE-2014-3691: Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request without a certificate.
nvd
CVE-2018-11219P3CRITICALCVSS 9.8v10v132018-06-17
CVE-2018-11219 [CRITICAL] CWE-190 CVE-2018-11219: An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.
nvd
CVE-2017-7466P3HIGHCVSS 8.0v10v112018-06-22
CVE-2017-7466 [HIGH] CWE-20 CVE-2017-7466: Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from c Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
nvd
CVE-2013-2166P3CRITICALCVSS 9.8v3.02019-12-10
CVE-2013-2166 [CRITICAL] CWE-326 CVE-2013-2166: python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
nvd
CVE-2013-2167P3CRITICALCVSS 9.8v3.02019-12-10
CVE-2013-2167 [CRITICAL] CWE-345 CVE-2013-2167: python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
nvd
CVE-2019-0223P3HIGHCVSS 7.4v13v142019-04-23
CVE-2019-0223 [HIGH] CVE-2019-0223: While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack cou
nvd
CVE-2019-16789P3HIGHCVSS 8.2v152019-12-26
CVE-2019-16789 [HIGH] CWE-444 CVE-2019-16789: In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid reques In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Specially crafted requests containing special whitespace characters in the Transfer-Encoding header would g
nvd