CVE-2015-5162
- EPSS 3.06%
- Veröffentlicht 07.10.2016 14:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk c...
CVE-2015-5163
- EPSS 1.5%
- Veröffentlicht 19.08.2015 15:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.
- EPSS 1.31%
- Veröffentlicht 14.08.2015 18:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them.
CVE-2013-4428
- EPSS 3.08%
- Veröffentlicht 27.10.2013 00:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated user...
CVE-2013-1840
- EPSS 1.37%
- Veröffentlicht 22.03.2013 21:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a reques...