Redhat

Openstack

212 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 7.31%
  • Veröffentlicht 23.05.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.

  • EPSS 1.58%
  • Veröffentlicht 23.05.2017 04:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture.

  • EPSS 0.08%
  • Veröffentlicht 23.05.2017 04:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.

  • EPSS 0.28%
  • Veröffentlicht 21.04.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form.

  • EPSS 1.46%
  • Veröffentlicht 31.03.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.

  • EPSS 5.55%
  • Veröffentlicht 31.03.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Snoopy allows remote attackers to execute arbitrary commands.

  • EPSS 2.69%
  • Veröffentlicht 31.03.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.

  • EPSS 0.09%
  • Veröffentlicht 27.03.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence.

Exploit
  • EPSS 1.38%
  • Veröffentlicht 15.03.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

  • EPSS 0.14%
  • Veröffentlicht 23.12.2016 22:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memo...