Vulnerabilities
Vulnerable Software
Redhat:  >> Openstack  >> 5.0  Security Vulnerabilities
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
CVSS Score
7.5
EPSS Score
0.045
Published
2015-06-15
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
CVSS Score
7.7
EPSS Score
0.286
Published
2015-05-13
The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.
CVSS Score
10.0
EPSS Score
0.067
Published
2015-04-10
The log-viewing function in the Red Hat redhat-access-plugin before 6.0.3 for OpenStack Dashboard (horizon) allows remote attackers to read arbitrary files via a crafted path.
CVSS Score
4.0
EPSS Score
0.002
Published
2015-03-10
Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request without a certificate.
CVSS Score
7.5
EPSS Score
0.004
Published
2015-03-09
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
CVSS Score
4.0
EPSS Score
0.01
Published
2015-01-23
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
CVSS Score
5.5
EPSS Score
0.007
Published
2015-01-07
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
CVSS Score
2.1
EPSS Score
0.001
Published
2014-11-01
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
CVSS Score
4.0
EPSS Score
0.007
Published
2014-10-31
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.
CVSS Score
4.0
EPSS Score
0.011
Published
2014-10-31


Contact Us

Shodan ® - All rights reserved