CVE-2016-9603
- EPSS 1.52%
- Veröffentlicht 27.07.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:29
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged...
CVE-2017-2620
- EPSS 0.77%
- Veröffentlicht 27.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:50
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use t...
CVE-2017-2621
- EPSS 0.07%
- Veröffentlicht 27.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:51
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive informa...
CVE-2017-2622
- EPSS 0.04%
- Veröffentlicht 27.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:51
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
CVE-2017-7539
- EPSS 1.79%
- Veröffentlicht 26.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:07
An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O coroutine was undefined. This could crash the qemu-nbd server if a client sent unexpected data during ...
CVE-2017-7543
- EPSS 0.22%
- Veröffentlicht 26.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:07
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the ...
- EPSS 0.38%
- Veröffentlicht 26.07.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:52
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no-authentication or encryption....
CVE-2017-2673
- EPSS 1.29%
- Veröffentlicht 19.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:57
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including ad...
CVE-2017-7481
- EPSS 3.69%
- Veröffentlicht 19.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:31:59
Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting ...
CVE-2018-2767
- EPSS 0.28%
- Veröffentlicht 18.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:04:24
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows low ...