Redhat

Openstack

214 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 04.11.2016 21:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request...

Exploit
  • EPSS 89.58%
  • Veröffentlicht 20.09.2016 18:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow loc...

  • EPSS 0.07%
  • Veröffentlicht 02.08.2016 16:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.

  • EPSS 0.63%
  • Veröffentlicht 12.07.2016 19:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to ...

  • EPSS 0.57%
  • Veröffentlicht 12.07.2016 19:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.

  • EPSS 0.11%
  • Veröffentlicht 30.06.2016 16:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which allows attacke...

  • EPSS 0.2%
  • Veröffentlicht 01.06.2016 22:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.

  • EPSS 0.06%
  • Veröffentlicht 25.05.2016 15:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).

  • EPSS 0.09%
  • Veröffentlicht 11.05.2016 21:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Port...

  • EPSS 0.34%
  • Veröffentlicht 15.04.2016 17:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which migh...