OpenStack / Folsom
25 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2013-4463 | Nova: Compressed disk image DoS | LOW | 2.1 | Feb 6, 2014 |
| CVE-2013-2030 | keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which al… | MEDIUM | 4.3 | Dec 27, 2013 |
| CVE-2013-4497 | openstack-nova: XenAPI security groups not kept through migrate or resize | MEDIUM | 6.4 | Nov 5, 2013 |
| CVE-2013-4469 | Nova: Incomplete fix for CVE-2013-2096 | LOW | 1.9 | Nov 2, 2013 |
| CVE-2013-4261 | OpenStack: openstack-nova-compute console-log DoS | LOW | 3.5 | Oct 29, 2013 |
| CVE-2013-4155 | OpenStack: Swift Denial of Service using superfluous object tombstones | MEDIUM | 4.0 | Aug 20, 2013 |
| CVE-2013-2161 | Swift: Unchecked user input in Swift XML responses | HIGH | 7.5 | Aug 20, 2013 |
| CVE-2013-2096 | Nova: fails to verify image virtual size denial of service | MEDIUM | 6.9 | Jul 9, 2013 |
| CVE-2013-1665 | bindings: External entity expansion in Python XML libraries inflicts potential security flaws and DoS vulnerabilities | MEDIUM | 5.0 | Apr 3, 2013 |
| CVE-2013-1664 | bindings: Internal entity expansion in Python XML libraries inflicts DoS vulnerabilities | MEDIUM | 5.0 | Apr 3, 2013 |
| CVE-2013-1865 | keystone: online validation of Keystone PKI tokens bypasses revocation check | MEDIUM | 6.9 | Mar 22, 2013 |
| CVE-2013-1838 | Nova: DoS by allocating all Fixed IPs | HIGH | 7.1 | Mar 22, 2013 |
| CVE-2013-0335 | Openstack nova: vnc proxy can connect to the wrong vm | HIGH | 7.1 | Mar 22, 2013 |
| CVE-2013-0266 | Puppetlabs-cinder: packstack: openstack: puppetlabs-cinder: information disclosure of openstack administrative passwords due to world-readable configuration fi… | MEDIUM | 5.5 | Mar 8, 2013 |
| CVE-2013-0261 | Packstack: packstack: arbitrary file overwrite via symlink attack | HIGH | 8.8 | Mar 8, 2013 |
| CVE-2013-0208 | openstack-nova: Boot from volume allows access to random volumes | MEDIUM | 6.5 | Feb 13, 2013 |
| CVE-2012-5625 | OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content… | MEDIUM | 6.5 | Dec 26, 2012 |
| CVE-2012-5571 | Openstack keystone: openstack keystone: authorization bypass via improper ec2 token handling | MEDIUM | 5.4 | Dec 18, 2012 |
| CVE-2012-5563 | OpenStack: Keystone extension of token validity through token chaining | HIGH | 8.2 | Dec 18, 2012 |
| CVE-2012-5482 | The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an i… | MEDIUM | 5.5 | Nov 11, 2012 |
| CVE-2012-4573 | OpenStack: Glance Authentication bypass for image deletion | MEDIUM | 5.5 | Nov 11, 2012 |
| CVE-2012-3447 | virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files… | HIGH | 7.1 | Aug 20, 2012 |
| CVE-2012-3361 | virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary file… | MEDIUM | 5.5 | Jul 22, 2012 |
| CVE-2012-3360 | Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors,… | MEDIUM | 5.5 | Jul 22, 2012 |
| CVE-2012-3371 | The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authent… | LOW | 3.5 | Jul 17, 2012 |
Showing 1 to 25 of 25 CVEs