- EPSS 0.43%
- Veröffentlicht 06.03.2014 15:55:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service (disk consumption) by creating and deleting instances with unique os_type settings, which tri...
CVE-2013-7048
- EPSS 0.06%
- Veröffentlicht 23.01.2014 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live snapshots.
- EPSS 0.34%
- Veröffentlicht 16.09.2013 19:14:38
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors...
CVE-2012-3447
- EPSS 0.93%
- Veröffentlicht 20.08.2012 18:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by ro...
- EPSS 0.48%
- Veröffentlicht 17.08.2012 00:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.
CVE-2012-2101
- EPSS 0.89%
- Veröffentlicht 07.06.2012 19:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network reques...
CVE-2012-0030
- EPSS 0.55%
- Veröffentlicht 13.01.2012 18:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified project_id URI parameter.
- EPSS 0.54%
- Veröffentlicht 23.12.2011 22:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method are enabled, allow remote authenticated users to overwrite arbitrary files via a crafted (1) tarball o...