cbcvebase.

Redhat Openstack vulnerabilities

208 known vulnerabilities affecting redhat/openstack.

Total CVEs
208
CISA KEV
0
Public exploits
9
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH63MEDIUM111LOW11

Vulnerabilities

Page 5 of 11
CVE-2018-11806P3HIGHCVSS 8.2v8v9+3 more2018-06-13
CVE-2018-11806 [HIGH] CWE-787 CVE-2018-11806: m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams. m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
nvd
CVE-2017-2627P3HIGHCVSS 8.2v10v112018-08-22
CVE-2017-2627 [HIGH] CWE-22 CVE-2017-2627: A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's openstack-tripleo-common package is much too permissive. It contains several lines for the mistral user that have wildcards that allow directory traversal with '..' and it grants full passwordless root access to th
nvd
CVE-2018-1000127P3HIGHCVSS 7.5v102018-03-13
CVE-2018-1000127 [HIGH] CWE-190 CVE-2018-1000127: memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in
nvd
CVE-2012-6685P3HIGHCVSS 7.5v4.0v6.02020-02-19
CVE-2012-6685 [HIGH] CWE-776 CVE-2012-6685: Nokogiri before 1.5.4 is vulnerable to XXE attacks Nokogiri before 1.5.4 is vulnerable to XXE attacks
nvd
CVE-2017-15139P3HIGHCVSS 7.5v10v132018-08-27
CVE-2017-15139 [HIGH] CWE-200 CVE-2017-15139: A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly cr A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
nvd
CVE-2018-16856P3HIGHCVSS 7.5v12v13+1 more2019-03-26
CVE-2018-16856 [HIGH] CWE-532 CVE-2018-16856: In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions ope In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
nvd
CVE-2017-10379P3MEDIUMCVSS 6.5v122017-10-19
CVE-2017-10379 [MEDIUM] CWE-863 CVE-2017-10379: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks
nvd
CVE-2016-2124P3MEDIUMCVSS 5.9v13v16.1+1 more2022-02-18
CVE-2016-2124 [MEDIUM] CWE-287 CVE-2016-2124: A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw t A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
nvd
CVE-2018-2668P3MEDIUMCVSS 6.5v122018-01-18
CVE-2018-2668 [MEDIUM] CVE-2018-2668: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2018-2622P3MEDIUMCVSS 6.5v122018-01-18
CVE-2018-2622 [MEDIUM] CVE-2018-2622: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2018-2665P3MEDIUMCVSS 6.5v122018-01-18
CVE-2018-2665 [MEDIUM] CVE-2018-2665: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2018-2640P3MEDIUMCVSS 6.5v122018-01-18
CVE-2018-2640 [MEDIUM] CVE-2018-2640: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2017-7980P3HIGHCVSS 7.8v6.0v7.0+4 more2017-07-25
CVE-2017-7980 [HIGH] CWE-119 CVE-2017-7980: Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.
nvd
CVE-2019-3830P3HIGHCVSS 7.8v102019-03-26
CVE-2019-3830 [HIGH] CWE-532 CVE-2019-3830: A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilo A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
nvd
CVE-2019-9735P3MEDIUMCVSS 6.5v10v13+1 more2019-03-13
CVE-2019-9735 [MEDIUM] CWE-755 CVE-2019-9735: An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x bef An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security gr
nvd
CVE-2013-1793P3HIGHCVSS 7.5v2.1v3.0+1 more2019-12-10
CVE-2013-1793 [HIGH] CWE-306 CVE-2013-1793: openstack-utils openstack-db has insecure password creation openstack-utils openstack-db has insecure password creation
nvd
CVE-2019-14433P3MEDIUMCVSS 6.5v10v13+1 more2019-08-09
CVE-2019-14433 [MEDIUM] CWE-209 CVE-2019-14433: An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2 An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
nvd
CVE-2019-10876P3MEDIUMCVSS 6.5v13v142019-04-05
CVE-2019-10876 [MEDIUM] CVE-2019-10876: An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) fire
nvd
CVE-2018-17205P3HIGHCVSS 7.5v10v132018-09-19
CVE-2018-17205 [HIGH] CWE-617 CVE-2018-17205: An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ i An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow action is a go-to for a group id that does not exist), OvS tries to revert back all previous flows tha
nvd
CVE-2018-2755P3HIGHCVSS 7.7v122018-04-19
CVE-2018-2755 [HIGH] CVE-2018-2755: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful a
nvd
Redhat Openstack vulnerabilities | cvebase