OpenStack / Nova
39 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2014-8333 | openstack-nova: Nova VMware instance in resize state may leak | MEDIUM | 4.0 | Oct 31, 2014 |
| CVE-2014-3708 | openstack-nova: Nova network denial of service through API filtering | MEDIUM | 4.0 | Oct 31, 2014 |
| CVE-2014-8750 | openstack-nova: Nova VMware driver may connect VNC to another tenant's console | MEDIUM | 6.5 | Oct 15, 2014 |
| CVE-2014-7231 | Trove: potential leak of passwords into log files | LOW | 2.1 | Oct 8, 2014 |
| CVE-2014-7230 | Trove: potential leak of passwords into log files | LOW | 2.1 | Oct 8, 2014 |
| CVE-2014-3608 | openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images | LOW | 2.7 | Oct 6, 2014 |
| CVE-2014-3517 | openstack-nova: timing attack issue allows access to other instances' configuration information | MEDIUM | 4.3 | Aug 7, 2014 |
| CVE-2013-6437 | openstack-nova: DoS through ephemeral disk backing files | MEDIUM | 4.0 | Mar 6, 2014 |
| CVE-2013-7048 | Nova: insecure directory permissions in snapshots | LOW | 3.3 | Jan 23, 2014 |
| CVE-2013-2256 | OpenStack: Nova private flavors resource limit circumvention | MEDIUM | 6.0 | Sep 16, 2013 |
| CVE-2012-3447 | virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files… | HIGH | 7.1 | Aug 20, 2012 |
| CVE-2012-1585 | OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long… | MEDIUM | 4.0 | Aug 17, 2012 |
| CVE-2012-2101 | Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain per… | LOW | 3.5 | Jun 7, 2012 |
| CVE-2012-0030 | Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI re… | MEDIUM | 4.9 | Jan 13, 2012 |
| CVE-2011-4596 | Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled… | MEDIUM | 6.0 | Dec 23, 2011 |
Showing 26 to 39 of 39 CVEs