Apache / Cloudstack
65 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2019-17562 | A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability… | CRITICAL | 9.8 | May 14, 2020 |
| CVE-2016-6813 | Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to det… | CRITICAL | 9.8 | Feb 6, 2018 |
| CVE-2013-4317 | cloudstack: Information disclosure in listProjectAccounts in the CloudStack API | MEDIUM | 4.3 | Feb 6, 2018 |
| CVE-2016-3085 | Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and use… | MEDIUM | 6.5 | Jun 10, 2016 |
| CVE-2015-3252 | Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by co… | CRITICAL | 9.8 | Feb 8, 2016 |
| CVE-2015-3251 | Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines v… | MEDIUM | 4.9 | Feb 8, 2016 |
| CVE-2014-9593 | Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call. | MEDIUM | 5.0 | Jan 15, 2015 |
| CVE-2014-7807 | Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which trig… | MEDIUM | 5.0 | Dec 10, 2014 |
| CVE-2013-2758 | Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, wh… | MEDIUM | 5.0 | May 23, 2014 |
| CVE-2013-2756 | Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the con… | MEDIUM | 5.0 | May 23, 2014 |
| CVE-2014-0031 | The (1) ListNetworkACL and (2) listNetworkACLLists APIs in Apache CloudStack before 4.2.1 allow remote authenticated users to list network ACLS for other users… | MEDIUM | 4.0 | Jan 14, 2014 |
| CVE-2013-6398 | The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote att… | LOW | 2.8 | Jan 14, 2014 |
| CVE-2013-2136 | Multiple cross-site scripting (XSS) vulnerabilities in Apache CloudStack before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1)… | MEDIUM | 4.3 | Aug 19, 2013 |
| CVE-2012-5616 | Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file,… | LOW | 1.5 | Jan 22, 2013 |
| CVE-2012-4501 | Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as d… | HIGH | 10.0 | Oct 26, 2012 |
Showing 51 to 65 of 65 CVEs