CVE-2011-3147
- EPSS 0.18%
- Veröffentlicht 22.04.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 01:29:50
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.
CVE-2017-18191
- EPSS 1.54%
- Veröffentlicht 19.02.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:31
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service at...
CVE-2017-17051
- EPSS 0.84%
- Veröffentlicht 05.12.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doub...
CVE-2017-16239
- EPSS 0.39%
- Veröffentlicht 14.11.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the I...
CVE-2017-7214
- EPSS 1.3%
- Veröffentlicht 21.03.2017 18:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as accoun...
CVE-2015-5162
- EPSS 3.2%
- Veröffentlicht 07.10.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk c...
CVE-2016-2140
- EPSS 0.63%
- Veröffentlicht 12.04.2016 14:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header ...
CVE-2015-8749
- EPSS 0.94%
- Veröffentlicht 15.01.2016 19:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attac...
CVE-2015-7548
- EPSS 0.17%
- Veröffentlicht 12.01.2016 19:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk wit...
- EPSS 1.52%
- Veröffentlicht 29.10.2015 20:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change ...