CVE-2012-4573
- EPSS 0.99%
- Veröffentlicht 11.11.2012 13:00:58
- Zuletzt bearbeitet 11.04.2025 00:51:21
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
CVE-2012-3447
- EPSS 0.93%
- Veröffentlicht 20.08.2012 18:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image that uses a symlink that is only readable by ro...
CVE-2012-3361
- EPSS 1.38%
- Veröffentlicht 22.07.2012 16:55:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.
CVE-2012-3360
- EPSS 2.57%
- Veröffentlicht 22.07.2012 16:55:45
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a .. (dot...
CVE-2012-3371
- EPSS 0.88%
- Veröffentlicht 17.07.2012 21:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of service (excessive database lookup calls and server hang)...